Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cybercrime-service-ecosystemcredential-stealer-activityremote-access-implantbotnet-infrastructure

Operation Endgame Disrupts Rhadamanthys, VenomRAT, and Elysium Malware Operations

Updated 2mo agoFirst seen Nov 13, 202536 sources

International law enforcement agencies, coordinated by Europol and Eurojust, executed a major crackdown on the infrastructures supporting the Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet. The operation, part of the ongoing Operation Endgame, resulted in the takedown of over 1,025 servers and the seizure of 20 domains used to control and distribute these malware families. Authorities also arrested the main suspect behind VenomRAT in Greece, and the dismantled infrastructure included hundreds of thousands of infected computers and millions of stolen credentials, with many victims unaware of the compromise. The operation involved law enforcement from at least nine countries and was supported by numerous private sector partners, including cybersecurity firms and threat intelligence organizations.

Rhadamanthys, a modular information stealer sold as malware-as-a-service, and VenomRAT, a commodity RAT favored by threat actors like TA558, were both widely distributed through email campaigns, malvertising, and other vectors. The Elysium botnet, less well-documented, was also linked to these operations, potentially serving as a proxy network for criminal activity. The disruption has caused significant operational issues for cybercriminals, with many reporting loss of access to their command-and-control panels and servers. Authorities have advised potential victims to check if their systems were compromised and to take remediation steps, as the takedown is expected to have a substantial impact on the cybercrime ecosystem.

Share:
Operation Endgame Disrupts Rhadamanthys, VenomRAT, and Elysium Malware Operations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Nov 13, 20257mo ago

Law enforcement and partners notify victims and criminal users

Following the takedown announcement, authorities and partners directed potential victims to breach-checking and compromise-notification services and said they had contacted users of the criminal services. The outreach was intended both to help exposed victims and to generate investigative leads on operators and customers.

Authorities publicly announce Rhadamanthys, VenomRAT, and Elysium disruption

On November 13, 2025, Europol and partner agencies publicly revealed the latest Operation Endgame takedowns affecting Rhadamanthys, VenomRAT, and the Elysium botnet. Officials also said the main infostealer suspect had access to more than 100,000 cryptocurrency wallets potentially worth millions of euros.

Operation Endgame seizes 1,025 servers and 20 domains

International law enforcement dismantled infrastructure used by Rhadamanthys, VenomRAT, and Elysium, taking down 1,025 servers and seizing 20 domains. Europol said the infrastructure had infected hundreds of thousands of computers and was tied to several million stolen credentials.

Nov 11, 20257mo ago

Rhadamanthys operators lose access to servers

Customers and operators of the Rhadamanthys malware-as-a-service platform lost access to their servers during the law enforcement disruption. Reporting indicated the developer suspected German law enforcement involvement after seeing German IP connections.

Nov 10, 20257mo ago

Searches conducted across Germany, Greece, and the Netherlands

Law enforcement carried out coordinated searches at 11 locations in Germany, Greece, and the Netherlands during the action days of Operation Endgame. These searches took place between November 10 and 14, 2025.

Operation Endgame begins new action phase

A new phase of Operation Endgame began on November 10, 2025, targeting infrastructure tied to the Rhadamanthys infostealer, VenomRAT, and the Elysium botnet. The multinational effort was coordinated by Europol and Eurojust.

Nov 3, 20258mo ago

Police arrest key VenomRAT suspect in Greece

Authorities arrested a main suspect linked to VenomRAT in Greece as part of Operation Endgame. Multiple reports place the arrest on November 3, 2025, ahead of the broader public announcement of the operation.

May 23, 20251y ago

Operation Endgame Season 2 officially launches

Operation Endgame "Season 2" was officially launched as a renewed international effort to disrupt botnet infrastructure and the operators behind it. Spamhaus said it supported the action with victim account remediation, while law enforcement and partners coordinated the broader campaign.

Malware Digest Sep 2023 | Stats for URLs, IOCs & malware from abuse.ch
May 30, 20242y ago

Operation Endgame first announced against major botnets

A coalition of international law enforcement agencies announced the original Operation Endgame on May 30, 2024, targeting major botnets including IcedID, SmokeLoader, SystemBC, Pikabot, and Bumblebee. The action marked the initial public launch of the multinational botnet disruption effort later followed by Season 2.

Malware Digest Dec 2022 | Stats for URLs, IOCs & malware from abuse.ch
Jan 1, 20224y ago

Rhadamanthys infostealer first observed

Proofpoint described Rhadamanthys as a malware-as-a-service infostealer first seen in 2022, used to steal credentials, financial data, and system information. It later became a tool used by multiple cybercriminal actors across email, web-inject, and malvertising campaigns.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

126 LINKEDOpen in app
Affected products
10 linked
AndroidNetscalerTelegramWindowsWindows 11PowershellTorAndroidAndroidAndroid
Organizations
56 linked
ProofpointEuropolHave I Been PwnedShadowServer FoundationCrowdStrikeCryptolaemusTA558SpyCloudLumen TechnologiesU.S. prosecutorsBitdefenderabuse.chDanaBot OperatorsGoogleCisco SystemsfbiEurojustBleepingComputerAmazon Web ServicesTeam CymruPoliceFederal Criminal Police Office (Germany)Australian Federal PoliceCheckout.compolitie.nlU.S. Department of JusticeCloudflareAnthropicRecorded FutureMeta PlatformsLovablehaveibeenpwned.comrcmpSpamhausDeepwatchXAppleMicrosoft CorporationDutch Institute for Vulnerability DisclosureDefense Criminal Investigative ServiceRoLRDIVDPublic Prosecutor General’s Office Frankfurt am Main – Cybercrime OfficeSûreté du QuébecPublic Prosecutor Office JUNALCOLithuanian Criminal Police BureauParis Police PrefectureNational Police (France)CymruDanish PoliceHellenic PoliceProwlerDutch Public Prosecution OfficeThe Spamhaus ProjectMacroPackOperationEndgame
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Operation Endgame Disrupts Rhadamanthys, VenomRAT, and Elysium Malware Operations | Mallory