Elysium
Elysium is malware consistently described in the provided content as a botnet, including as a relatively unknown proxy bot and as botnet infrastructure or an ecosystem used in international cybercrime. The content states that Elysium linked victim machines into controlled networks that could support distributed attacks, anonymity services, and scalable malware deployment. It is repeatedly mentioned alongside the Rhadamanthys infostealer and the VenomRAT remote access trojan as part of the same criminal infrastructure targeted by Europol-led Operation Endgame in November 2025. According to the content, authorities from multiple countries disrupted or took down Elysium between 10 and 13 November 2025, seizing or disabling more than 1,000 servers overall across the targeted malware families and seizing 20 domains. Europol is cited as stating that the targeted malware families, including Elysium, had infected hundreds of thousands of computers globally, enabled credential theft, remote access, and resale of stolen data, and played a key role in international cybercrime. One source in the content also describes Elysium as the enabler of the Rhadamanthys infostealer and VenomRAT. Another source characterizes it as a botnet variant of the Ghost ransomware family active since 2021. High-confidence indicators of compromise specific to Elysium are not provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Recent activity
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet whose core infrastructure was terminated in a prior Operation Endgame action.
Named botnet malware operation targeted by Operation Endgame.
A botnet described as a large cybercrime enabler targeted during Operation Endgame.
Botnet disrupted as part of Operation Endgame.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.