International law enforcement and industry partners expanded Operation Endgame to dismantle malware infrastructure tied to infostealers, botnets, remote access trojans, and ransomware enablement. Europol said a 2025 follow-up used a database seized in the 2024 takedown to identify customers of the Smokeloader pay-per-install botnet, resulting in five detentions and interrogations, house searches, arrest warrants, and so-called knock-and-talk actions across Europe and North America. Investigators said access bought through Smokeloader was used for keylogging, webcam access, cryptomining, and ransomware deployment, signaling that authorities are now pursuing not only operators but also downstream criminal users.
Dutch police later reported another coordinated Endgame action that included the arrest in Greece of a main suspect linked to VenomRAT, 11 searches, the takedown of 1,025 servers, and the seizure of 20 domains. Authorities said the disrupted malware families had infected more than 600,000 victims worldwide and enabled the theft of tens of millions of records; stolen user data was secured and made inaccessible, with victims directed to a police portal to check exposed credentials. Separate technical reporting on DanaBot described the malware-as-a-service platform as a stealthy, multi-tier operation with roughly 150 active C2 servers per day across more than 40 countries, and said its disruption under Operation Endgame II was the most significant blow to the botnet to date.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Europol announced that follow-up actions tied to Operation Endgame had led to five detentions and interrogations, using leads from the previously seized Smokeloader database to link online personas to real individuals.
In 2025, Operation Endgame II dealt what Team Cymru described as the most significant disruption to DanaBot to date through coordinated action by law enforcement, industry partners, and hosting providers.
In early 2025, law enforcement agencies in North America and Europe carried out follow-up actions against customers of the Smokeloader pay-per-install botnet, including arrests, house searches, arrest warrants, and knock-and-talks.
DanaBot activity hit all-time highs during the December 2024 holiday period, according to Team Cymru’s infrastructure analysis.
Researchers observed DanaBot activity increase by nearly 50 command-and-control servers before the November 2024 U.S. election.
Team Cymru reported that DanaBot’s upstream and backend infrastructure had remained largely unchanged since June 2024, indicating operational continuity ahead of later disruption efforts.
During Operation Endgame in May 2024, authorities targeted major malware droppers including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. A database seized in that action later helped investigators identify Smokeloader customers.
DanaBot was first reported in 2018 as a banking trojan before later evolving into an infostealer and malware delivery platform.
Dutch police said they secured stolen user data, including email addresses and login credentials, made it inaccessible, and directed the public to a police website to check whether their credentials were included.
As part of the Operation Endgame actions, authorities arrested a main suspect linked to VenomRAT in Greece.
Authorities from ten countries conducted coordinated Operation Endgame actions that included 11 searches, the takedown of 1,025 servers worldwide, and the seizure of 20 domains targeting infostealers, botnets, RATs, and related criminal services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
politie.nl
Open sourceoperation-endgame.com
Open sourceteam-cymru.com
Open sourceeuropol.europa.eu
Open sourceesentire.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.