US Cyber Command says it has temporarily disrupted the Trickbot botnet, an army of 1M+ hijacked computers run by Russian-speaking criminals, ahead of elections
Ellen Nakashima / Washington Post :
Context & Ripple Effects
This is US Cyber Command's second known overseas operation to defend an election: it first targeted Russian operatives spreading disinformation in 2018, and two years later went after infrastructure rather than influence operations. The target was Trickbot, a botnet of over a million hijacked machines whose droppers ran as malware-as-a-service, distributing ransomware payloads via infected email.
The military action landed alongside a parallel private-sector effort: a coalition led by Microsoft with Symantec, ESET, and others orchestrated its own takedown days later. But the disruption proved temporary — some command and control servers stayed online despite Microsoft's legal action, and by mid-2021 Bitdefender reported the operators had quietly rebuilt much of the operation.
First-order effects
- Trickbot operators lose their command-and-control reach over 1M+ infected machines for at least as long as the disruption holds, blunting both ransomware distribution and any pre-election mischief the infrastructure could enable.
- Microsoft, Symantec, and ESET gain legal cover to seize or sinkhole botnet infrastructure, converting Cyber Command's temporary disruption into a sustained industry-side pressure campaign.
Second-order effects
- Because Trickbot's droppers operated as malware-as-a-service feeding ransomware crews, downstream ransomware buyers lose payload delivery for the duration — pushing affiliates toward alternative infection channels until the botnet recovers.
- The partial failure documented by Krebs on Security forces the coalition model to evolve from one-off takedowns toward continuous monitoring, since servers that survive a strike can re-register and reconnect infected machines.
Third-order effects
- If every disruption is followed by a quiet rebuild, as Bitdefender reported within months, botnet takedowns shift from permanent victories to recurring cost-imposition — making durable attribution leaks like the internal Trickleaks cache as strategically valuable as server seizures themselves.
- Cyber Command's progression from 2018 disinformation deterrence to 2020 infrastructure attack normalizes military action against criminal (not just state) networks ahead of elections, setting a template other nations may follow.
The trend: Election-threat defense is expanding from counter-disinformation to direct military-plus-industry strikes on criminal cyber infrastructure, even as malware-as-a-service operators prove able to rebuild after each disruption.