Dutch authorities shut down 143 command-and-control servers tied to the Bredolab botnet and arrested a suspected operator in Yerevan, Armenia, disrupting a malware distribution network that police said had infected roughly 30 million computers worldwide. First identified as a downloader operation and later expanded into a botnet, Bredolab spread through compromised legitimate websites, obfuscated JavaScript including Trojan-Downloader.JS.Pegel, and exploit kits targeting vulnerabilities in Adobe Reader, Java, and MDAC.
The botnet acted primarily as a malware delivery platform, installing additional payloads for partners such as Zbot, SpyEyes, TDSS, and ransomware, while also stealing FTP credentials with Trojan-PSW.Win32.Agent.qgg to compromise more websites and sustain infections. Its operators used fast-flux and double-flux proxy infrastructure to hide backend systems, illustrating how website compromise, traffic redirection, exploit delivery, credential theft, and resilient hosting combined to make Bredolab one of the era’s largest criminal malware operations.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
A person formerly responsible for running the Bredolab botnet was arrested at Yerevan international airport in Armenia the day after the server takedown. The arrest followed the Dutch action against the botnet's infrastructure.
Dutch authorities announced the shutdown of 143 Bredolab botnet control servers. Police said the botnet comprised about 30 million infected computers worldwide.
In summer 2010, Bredolab operators reverted from Pegel-based delivery back to hidden iframe tags on compromised websites. This marked another change in the botnet's web-based infection chain.
In late 2009, Bredolab operators replaced hidden iframes on compromised websites with obfuscated JavaScript known as Trojan-Downloader.JS.Pegel. The script decrypted in the browser and inserted links to malicious exploit resources into web pages.
By mid-2009, Bredolab had developed from malware into a botnet operation. It functioned primarily as a downloader that installed additional malware on victim systems.
Security researchers first detected the Backdoor.Win32.Bredolab malware in mid-2008. The malware later became the core loader used by the broader Bredolab operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.