An international law enforcement operation dubbed Operation Endgame disrupted major malware delivery and botnet infrastructure tied to IcedID, SmokeLoader, SystemBC, Pikabot, Trickbot, and remnants of Bumblebee, in what Europol and participating agencies described as the largest action of its kind against botnets. Authorities said the networks had been used to spread malware through hundreds of millions of phishing emails and to enable follow-on ransomware attacks and financial fraud, with investigators identifying several million infected computers worldwide over the past year.
The coordinated action, supported by Europol and Eurojust, took down more than 100 servers, seized over 2,000 domains, and disinfected more than 10,000 infected systems, while additional operations across multiple countries led to arrests, interrogations, searches, and server seizures. Investigators also identified a key suspect allegedly linked to 69 million euros in cryptocurrency proceeds, and separate reporting and research highlighted scrutiny of a SmokeLoader actor targeted as part of the crackdown.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Analyst1 published research examining the life and personality of a SmokeLoader actor said to have been targeted by Operation Endgame. The report added attribution-focused detail around one of the individuals linked to the disrupted malware ecosystem.
Authorities said they had identified a main suspect allegedly connected to 69 million euros in cryptocurrency earnings from the criminal activity. They stated that the assets would be seized as soon as possible.
As part of Operation Endgame, law enforcement and partners reported disinfecting more than 10,000 infected computers. The cleanup accompanied the broader disruption of malware delivery infrastructure used to enable ransomware and financial fraud.
Authorities, supported by Europol and Eurojust, took down more than 100 servers and seized over 2,000 domains during the operation. Additional police actions in several countries included arrests, interrogations, searches, and server seizures.
An international law enforcement action dubbed Operation Endgame targeted criminal infrastructure tied to IcedID, SmokeLoader, SystemBC, Pikabot, Trickbot, and remnants of Bumblebee. The operation was described as the largest coordinated action to date against malware botnets and their supporting infrastructure.
Investigators reported that several million infected computers linked to the targeted malware ecosystems had been identified worldwide over the prior year. The infections were associated with botnets including IcedID, SmokeLoader, SystemBC, Pikabot, Trickbot, and Bumblebee remnants.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
analyst1.com
Open sourcespamhaus.org
Open sourcetherecord.media
Open sourceeuropol.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.