Large-Scale Sting Tied to Operation Endgame Disrupts Ransomware Infrastructure
- From May 19 to 22, 2025, a coordinated global effort led by multiple law enforcement agencies successfully disrupted ransomware operations by shutting down around 300 servers and disabling 650 domains as part of Operation Endgame.
- This phase of Operation Endgame followed the May 2024 launch and was driven by the need to target initial access brokers fueling ransomware attacks through malware such as Bumblebee, Qakbot, and DanaBot.
- The coordinated effort, involving Europol, Eurojust, and multiple countries including the US, Germany, and the UK, included issuing 20 international arrest warrants and seizing over €21.2 million including €3.5 million in cryptocurrency.
- Catherine De Bolle, Europol’s executive director, emphasized that law enforcement is effectively countering cybercriminals by targeting the infrastructure they use for ransomware attacks, thereby interrupting the attack process at its foundation.
- The operation disrupted key cybercriminal ecosystems, including targeting suspected coordinators like Rustam Rafailevich Gallyamov and aims to impede ransomware attacks by removing access providers and maintaining sustained law enforcement campaigns.
21 Articles
21 Articles
Large-scale sting tied to Operation Endgame disrupts ransomware infrastructure
Law enforcement agencies from Europe and North America have dismantled key infrastructure behind several leading malware strains used in ransomware attacks, the latest action in a yearslong effort to combat cybercriminals. The operation, conducted as part of Operation Endgame, targeted the early stages of the cybercrime chain, focusing on initial access malware. The coordinated effort resulted in the takedown of approximately 300 servers and th…
Cybercrime: 20 Arrest Warrants Issued and 300 Servers Disabled During a Large-Scale Operation
Operation Endgame 2.0, conducted this week by Europol and Eurojust, targets software as a gateway to ransomware, and the European authorities hope to cut off the momentum of criminal networks that cause multiple cyberattacks.
Operation Endgame: EU, US authorities dismantle global malware network, taking down 300 servers and charging 20 suspects
PARIS, May 23 — European, American and Canadian authorities have taken down over 300 servers worldwide and issued international arrest warrants against 20 suspects in a crackdown on malware, EU agency for criminal justice cooperation Eurojust said in a statement, the latest phase in Operation Endgame. By the numbers German, French, Dutch, Danish, British, American and Canadian authorities joined forces this week against the world’s most dangerou…
Dutch police contribute to operation taking down 300 servers used by cybercriminals
International investigation agencies took down over 300 servers globally this week, which resulted in cybercriminals being unable to reach their systems. Of these, 60 servers were in data centers in the Netherlands. International police agencies are using the long-running Operation Endgame to press on their fight against ransomware, Dutch police have stated.By taking down the servers, several botnets were also made unavailable for use. A botnet …


Operation Endgame Takes Down DanaBot Malware, Neutralizes 300 Servers
Operation Endgame takes down DanaBot malware network; 300 servers neutralized, €21.2M in crypto seized, 16 charged, 20 international warrants.
Coverage Details
Bias Distribution
- 50% of the sources lean Right
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage