In a coordinated operation that took place during the week of May 19–22, law enforcement agencies from around the world dismantled some of the most dangerous malware operations. The operation, under the umbrella of Operation Endgame 2.0, yielded impressive results: over 300 servers were taken down, 650 domains were neutralized, international arrest warrants for 20 defendants , and digital assets worth over €3.5 million were seized.

Eurojust and Europol have been supporting the authorities’ operation since 2024. This year’s phase of the operation focused on eliminating new versions and variants of well-known , malware such as Qakbot , Bumblebee , Lactrodectus , DanaBot , HijackLoader , Trickbot and WarmCookie . These are so-called “initial access malware” – software that constitutes the first phase of a cyberattack and prepares the ground for the installation of ransomware or other control tools.
See also: Authorities disrupted Lumma Stealer malware infrastructure
Neutralizing such tools causes ripple effects in the “Cybercrime-as-a-Service”, affecting critical infrastructure of criminal networks and limiting the spread of new attacks.
Global coordination with the support of Europol & Eurojust
The operation was coordinated by Europol and Eurojust, which ensured legal cooperation, real-time information exchange and enhanced operational action. Eurojust has been providing critical support to complex cross-border investigations since 2024, ensuring effective cooperation between authorities.
In addition to European countries (Germany, France, the Netherlands, Denmark), the USA , Canada , and the United Kingdom actively participated in Operation Endgame 2.0 , to destroy the malware and identify its malicious users.
Results and next steps
During the action week:
- 37 people identified as suspects, 20 of whom face criminal charges
- Over 3.5 million euros in digital currencies were seized, bringing the total amount of Operation Endgame to 21.2 million euros.
- Hundreds of malware control infrastructures “broke down” (over 300 servers and 650 domains)
The operation does not end here. The international coalition has already begun follow-up and disclosure phases for the main suspects. German authorities are to add 18 names to the EU's most wanted list, starting May 23.
See also: 270 people arrested for illegal activities on the dark web

Who participated in “Operation Endgame 2.0”?
The coordinated operation brought together the following services:
- 🇩🇪 Germany: German Federal Criminal Police Office; Public Prosecutor? General's Office Frankfurt am Main – Cybercrime Office; German Federal Office for Information Security
- 🇫🇷 France: PPO Paris section J3 (Cybercrime Unit); BL2C (Cybercrime unit Préfecture de Police); OFAC (National Office against Cybercriminality)
- 🇳🇱 Netherlands: Netherlands Public Prosecution Service (National Office); Netherlands Police
- 🇩🇰 Denmark: National Special Crime Unit – NSK; NC3 | High Tech Crime
- 🇬🇧 United Kingdom: National Crime Agency
- 🇺🇸 USA: Federal Bureau of Investigation (FBI); US Department of Justice's Computer Crime and Intellectual Property Section; US Attorney's Office for the Central District of California
- 🇨🇦Canada : Royal Canadian Mounted Police (RCMP )
Operation Endgame 2.0 is one of the most significant and crucial international interventions in the field of cybersecurity in recent years. It is a clear message that international cooperation in cyberspace is not only feasible, but also effective against modern digital threats.
See also: US: Charges against creator of Qakbot botnet
The publication of wanted persons and the active participation of organizations such as Europol and Eurojust strengthens the trust of citizens and businesses that the rule of law has a say and a role in the digital world as well.
However, cybercriminals are always adapting. Every day we see new malware variants emerge. The operation is clearly successful, but it is not the end – it is an important battle, not the war.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.eurojust.europa.eu
