International law enforcement agencies, coordinated by Europol and Eurojust, executed a major crackdown on the infrastructures supporting the Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet. The operation, part of the ongoing Operation Endgame, resulted in the takedown of over 1,025 servers and the seizure of 20 domains used to control and distribute these malware families. Authorities also arrested the main suspect behind VenomRAT in Greece, and the dismantled infrastructure included hundreds of thousands of infected computers and millions of stolen credentials, with many victims unaware of the compromise. The operation involved law enforcement from at least nine countries and was supported by numerous private sector partners, including cybersecurity firms and threat intelligence organizations.
Rhadamanthys, a modular information stealer sold as malware-as-a-service, and VenomRAT, a commodity RAT favored by threat actors like TA558, were both widely distributed through email campaigns, malvertising, and other vectors. The Elysium botnet, less well-documented, was also linked to these operations, potentially serving as a proxy network for criminal activity. The disruption has caused significant operational issues for cybercriminals, with many reporting loss of access to their command-and-control panels and servers. Authorities have advised potential victims to check if their systems were compromised and to take remediation steps, as the takedown is expected to have a substantial impact on the cybercrime ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Following the takedown announcement, authorities and partners directed potential victims to breach-checking and compromise-notification services and said they had contacted users of the criminal services. The outreach was intended both to help exposed victims and to generate investigative leads on operators and customers.
On November 13, 2025, Europol and partner agencies publicly revealed the latest Operation Endgame takedowns affecting Rhadamanthys, VenomRAT, and the Elysium botnet. Officials also said the main infostealer suspect had access to more than 100,000 cryptocurrency wallets potentially worth millions of euros.
International law enforcement dismantled infrastructure used by Rhadamanthys, VenomRAT, and Elysium, taking down 1,025 servers and seizing 20 domains. Europol said the infrastructure had infected hundreds of thousands of computers and was tied to several million stolen credentials.
Customers and operators of the Rhadamanthys malware-as-a-service platform lost access to their servers during the law enforcement disruption. Reporting indicated the developer suspected German law enforcement involvement after seeing German IP connections.
Law enforcement carried out coordinated searches at 11 locations in Germany, Greece, and the Netherlands during the action days of Operation Endgame. These searches took place between November 10 and 14, 2025.
A new phase of Operation Endgame began on November 10, 2025, targeting infrastructure tied to the Rhadamanthys infostealer, VenomRAT, and the Elysium botnet. The multinational effort was coordinated by Europol and Eurojust.
Authorities arrested a main suspect linked to VenomRAT in Greece as part of Operation Endgame. Multiple reports place the arrest on November 3, 2025, ahead of the broader public announcement of the operation.
Operation Endgame "Season 2" was officially launched as a renewed international effort to disrupt botnet infrastructure and the operators behind it. Spamhaus said it supported the action with victim account remediation, while law enforcement and partners coordinated the broader campaign.
A coalition of international law enforcement agencies announced the original Operation Endgame on May 30, 2024, targeting major botnets including IcedID, SmokeLoader, SystemBC, Pikabot, and Bumblebee. The action marked the initial public launch of the multinational botnet disruption effort later followed by Season 2.
Proofpoint described Rhadamanthys as a malware-as-a-service infostealer first seen in 2022, used to steal credentials, financial data, and system information. It later became a tool used by multiple cybercriminal actors across email, web-inject, and malvertising campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
37 references tracked. Mallory keeps watching after this page renders.
troyhunt.com
Open sourcenews.risky.biz
Open sourcego.theregister.com
Open sourcehelpnetsecurity.com
Open sourcespamhaus.org
Open sourcespamhaus.org
Open sourcespamhaus.org
Open sourcespamhaus.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.