Elysium is a botnet, also described in the content as a relatively unknown proxy bot and a botnet ecosystem, that played a key role in international cybercrime. It was repeatedly identified alongside Rhadamanthys and VenomRAT as a target of Europol-coordinated Operation Endgame. In the November 2025 phase of that operation, authorities from multiple countries disrupted Elysium’s infrastructure by taking down or disabling more than 1,000 servers worldwide and seizing 20 domains; reporting also references 1,025 servers and 11 searches, with one key suspect arrested in Greece in connection with the broader operation. Europol described Elysium as infrastructure that links victim machines into controlled networks for distributed attacks, anonymity services, and scalable malware deployment. The content states that Elysium, together with Rhadamanthys and VenomRAT, had infected hundreds of thousands of computers globally and enabled cybercriminal activity at scale. One report also notes that a revived RHAD Security site appeared to advertise Elysium alongside Rhadamanthys and a crypter service after the takedown. High-confidence indicators in the provided content are limited to the malware names and associated seized infrastructure; no specific file hashes, domains, or other technical IOCs for Elysium itself are provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.
Malware operation/infrastructure previously targeted by Operation Endgame.
A botnet whose core infrastructure was terminated in a prior Operation Endgame action.
Named botnet malware operation targeted by Operation Endgame.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.