Topic: operation endgame
-
Operation Endgame disrupts Amadey and StealC malware operations
A coordinated international law enforcement effort under Operation Endgame dismantled key infrastructure for the Amadey and StealC malware operations, impacting 326 servers and 142 domains, and recovering over €41 million in cryptocurrency and 27 million stolen credentials. The operation, involvi...
Read More » -
Police Take Down StealC & Amadey Malware Networks
Operation Endgame dismantled the infrastructure behind the StealC and Amadey malware families, seizing 326 servers and 142 domains, and freezing over 41 million euros in crypto assets. Microsoft used the RICO Act to charge multiple enablers involved in both malware operations, which together infe...
Read More » -
Police clean 15,000 Evil Corp-linked SocGholish malware sites
International law enforcement dismantled nearly 15,000 compromised WordPress websites and over 100 servers linked to the SocGholish botnet and the Russian cybercrime group Evil Corp, as part of the ongoing Operation Endgame initiative. The SocGholish malware operates by hijacking legitimate WordP...
Read More » -
Police Takedown: Rhadamanthys, VenomRAT, and Elysium Malware Operations Disrupted
An international law enforcement effort led by Europol and Eurojust dismantled over 1,000 servers used by major malware families like Rhadamanthys, VenomRAT, and the Elysium botnet, with support from nine countries and private cybersecurity firms. The operation resulted in the arrest of a key sus...
Read More » -
Operation Endgame Hits Malware Linked to Top Ransomware Gang
A coordinated law enforcement operation called Operation Endgame dismantled the SocGholish malware distribution network, which had compromised roughly 15,000 websites through a botnet, leading to the seizure of 106 servers and domains. The takedown is significant because SocGholish served as a ga...
Read More » -
Operation Endgame 3.0 Takes Down Three Major Malware Networks
Operation Endgame 3.0 dismantled three major malware networks—Rhadamanthys, VenomRAT, and Elysium—through a coordinated international law enforcement effort across eleven countries. The operation disrupted over 1025 servers, seized 20 domains, and led to the arrest of the suspected VenomRAT opera...
Read More » -
DanaBot Malware Returns to Target Windows After 6-Month Hiatus
DanaBot malware has re-emerged with a new version (v669) after a six-month hiatus, now utilizing Tor-based infrastructure and cryptocurrency addresses for stolen funds. Originally a banking trojan distributed as malware-as-a-service, it evolved into a modular threat targeting credentials and cryp...
Read More » -
Cybercriminals Lose Control: Rhadamanthys Infostealer Shut Down
The Rhadamanthys infostealer malware service has been disrupted, with criminal subscribers losing access to their data-collection servers, possibly due to law enforcement actions by German authorities. Subscribers reported that their administrative panels now require certificate-based authenticat...
Read More » -
Law Enforcement Takedown Hits SocGholish: 106 Servers Down, 15,000 Sites Cleaned
An international law enforcement operation called "Operation Endgame" seized 106 servers and domains and cleaned nearly 15,000 compromised websites, dealing a severe blow to the "SocGholish malware operation", which tricked users via fake browser update prompts. The "TA569" group, linked to...
Read More » -
Attackers Hosted Fake Claude Download Page on claude.ai Domain
A threat actor exploited Anthropic's Claude Artifacts feature to host a fake download page on the legitimate claude.ai domain, tricking users from a sponsored Bing ad into downloading the SectopRAT remote access trojan, compromising at least 29 organizations over two days in July. The attack used...
Read More » -
Dutch Police Seize 250 Servers in Bulletproof Hosting Crackdown
Dutch law enforcement dismantled a major bulletproof hosting service used exclusively by cybercriminals, seizing approximately 250 physical servers and taking thousands of virtual servers offline. The service facilitated serious criminal activities like ransomware, botnets, and phishing by ignori...
Read More » -
VPN Credentials Fuel 50% of Ransomware Attacks
Ransomware activity surged in Q3 2025, with compromised VPN credentials being the primary entry point for nearly half of all breaches, driven mainly by three groups: Akira, Qilin, and INC Ransomware. The Akira group specifically targeted SonicWall appliances using credential stuffing attacks, exp...
Read More »