Authorities have identified clients of the Smokeloader malware botnet and arrested at least five people.

Last year, law enforcement seized more than 100 servers used to run known malware (e.g. IcedID, Pikabot, Trickbot, Bumblebee, Smokeloader, SystemBC). This was done as part of Operation Endgame.
Now, Europol says the operation is continuing with officers analyzing data from the seized servers and identifying clients of the malicious businesses (hackers who rented the malware to carry out attacks).
See also: Arrests of people for crypto investment fraud via AI
The agency did not provide details about the people arrested and says the new investigation also led to interrogations and server takedowns.
According to researchers, Smokeloader was run by a threat actor using the alias “Superstar.” The operator provided the botnet as a pay-per-install service, allowing customers to access victims’ machines.
Smokeloader has been used by hackers for various cybercriminal activities, from deploying ransomware and running cryptominers to accessing webcams and logging keystrokes.
See also: Garantex manager arrested in India
Some of the suspects chose to cooperate with law enforcement and allowed the examination of digital evidence that was on their personal devices.
As Operation Endgame continues, Europol has created a dedicated website to share the latest news. In addition, Europol has published a series of videos depicting officers’ activity and how they are identifying partners and clients of the Smokeloader malware.

Europol encourages anyone with information about criminal activities to contact authorities via the Operation Endgame website.
See also: Suspected hacker arrested for leaking data of 90 companies
The fact that authorities managed to not only identify but also arrest Smokeloader customers – that is, people who were using it for malicious purposes – is significant for two reasons:
- Shows progress in detection and prosecution tactics: Traditionally, creators and users of such tools move on the dark web with great caution, but the arrest of five people shows that security networks are starting to break more easily.
- It is a deterrent: These arrests send the message that there is no complete impunity for cybercrime – even for “customers”, not just for malware creators.
Operations, such as Operation Endgame, are important in tackling cybercrime.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
