As part of Operation Endgame , law enforcement from nine countries destroyed over 1,000 servers used by the Rhadamanthys infolstealer, VenomRAT and Elysium botnet malware operations .

The joint action, coordinated by Europol and Eurojust, was supported by many private partners, including Cryptolaemus, Shadowserver, Spycloud, Cymru, Proofpoint, CrowdStrike, Lumen, Abuse.ch, HaveIBeenPwned, Spamhaus, DIVD and Bitdefender.
Rhadamanthys, VenomRAT and Elysium in the sights of the authorities
From November 10 to 14, 2025, police conducted searches at 11 locations in Germany, Greece, and the Netherlands, seized 20 domains, and destroyed 1,025 servers used by the targeted malware operations.
See also: How attackers turn SVG files into phishing bait
This phase of Operation Endgame also led to the arrest of a key suspect in Greece on November 3, 2025, linked to the VenomRAT remote access trojan.
“ The compromised malware infrastructure consisted of hundreds of thousands of infected computers containing several million stolen credentials ,” Europol said in a press release on Thursday

“Many of the victims were unaware of the infection on their systems. The main suspect behind the infostealer had access to over 100,000 cryptocurrency wallets belonging to these victims, potentially worth millions of euros.“.
Europol also recommended using the websites politie.nl/checkyourhack and haveibeenpwned.com to check whether computers were infected with this malware.
See also: DanaBot malware returns after 6 months
Rhadamanthys infolstealer shutdown
Today's announcement confirms BleepingComputer's report from Tuesday that the operation Rhadamanthys infolstealer, with customers of the malware-as-a-service reporting that they no longer have access to their servers.
The Rhadamanthys developer also suggested in a Telegram message that German police may have been behind the outage, as web panels hosted in EU data centers recorded German IP addresses before the cybercriminals lost access.
Operation Endgame has targeted multiple malware operations, taking over 100 servers used by various malware operations, including IcedID, Bumblebee, Pikabot, Trickbot, and SystemBC.
See also: Lighthouse: Google targets group that sends spam messages

The joint action has also targeted ransomware infrastructures , the AVCheck website , clients and servers of the Smokeloader botnet , and other major malware operations, including DanaBot, IcedID, Pikabot, Trickbot, Smokeloader, Bumblebee, and SystemBC .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In April 2024, Ukrainian cyber police arrested a Russian in Kiev for working with ransomware companies Conti and LockBit (to make their malware undetectable by antivirus software).
