HomeSecurityPolice Target Rhadamanthys, VenomRAT & Elysium Malware - Arrests and...

Police target Rhadamanthys, VenomRAT & Elysium malware – Arrests also made in Greece

As part of Operation Endgame , law enforcement from nine countries destroyed over 1,000 servers used by the Rhadamanthys infolstealer, VenomRAT and Elysium botnet malware operations .

Rhadamanthys, VenomRAT & Elysium

The joint action, coordinated by Europol and Eurojust, was supported by many private partners, including Cryptolaemus, Shadowserver, Spycloud, Cymru, Proofpoint, CrowdStrike, Lumen, Abuse.ch, HaveIBeenPwned, Spamhaus, DIVD and Bitdefender.

Rhadamanthys, VenomRAT and Elysium in the sights of the authorities

From November 10 to 14, 2025, police conducted searches at 11 locations in Germany, Greece, and the Netherlands, seized 20 domains, and destroyed 1,025 servers used by the targeted malware operations.

See also: How attackers turn SVG files into phishing bait

This phase of Operation Endgame also led to the arrest of a key suspect in Greece on November 3, 2025, linked to the VenomRAT remote access trojan.

“ The compromised malware infrastructure consisted of hundreds of thousands of infected computers containing several million stolen credentials ,” Europol said in a press release on Thursday

Police target Rhadamanthys, VenomRAT & Elysium malware - Arrests also in Greece

“Many of the victims were unaware of the infection on their systems. The main suspect behind the infostealer had access to over 100,000 cryptocurrency wallets belonging to these victims, potentially worth millions of euros.“.

Europol also recommended using the websites politie.nl/checkyourhack and haveibeenpwned.com to check whether computers were infected with this malware.

See also: DanaBot malware returns after 6 months

Rhadamanthys infolstealer shutdown

Today's announcement confirms BleepingComputer's report from Tuesday that the operation Rhadamanthys infolstealer, with customers of the malware-as-a-service reporting that they no longer have access to their servers.

The Rhadamanthys developer also suggested in a Telegram message that German police may have been behind the outage, as web panels hosted in EU data centers recorded German IP addresses before the cybercriminals lost access.

Operation Endgame has targeted multiple malware operations, taking over 100 servers used by various malware operations, including IcedID, Bumblebee, Pikabot, Trickbot, and SystemBC.

See also: Lighthouse: Google targets group that sends spam messages

Police target Rhadamanthys, VenomRAT & Elysium malware - Arrests also in Greece

The joint action has also targeted ransomware infrastructures , the AVCheck website , clients and servers of the Smokeloader botnet , and other major malware operations, including DanaBot, IcedID, Pikabot, Trickbot, Smokeloader, Bumblebee, and SystemBC .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In April 2024, Ukrainian cyber police arrested a Russian in Kiev for working with ransomware companies Conti and LockBit (to make their malware undetectable by antivirus software).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS