Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructureloader-delivery-mechanismcybercrime-service-ecosystemenforcement-action

Operation Endgame Disrupts IcedID, SmokeLoader, Trickbot and Other Malware Botnets

Updated 27d agoFirst seen Apr 11, 20264 sources

An international law enforcement operation dubbed Operation Endgame disrupted major malware delivery and botnet infrastructure tied to IcedID, SmokeLoader, SystemBC, Pikabot, Trickbot, and remnants of Bumblebee, in what Europol and participating agencies described as the largest action of its kind against botnets. Authorities said the networks had been used to spread malware through hundreds of millions of phishing emails and to enable follow-on ransomware attacks and financial fraud, with investigators identifying several million infected computers worldwide over the past year.

The coordinated action, supported by Europol and Eurojust, took down more than 100 servers, seized over 2,000 domains, and disinfected more than 10,000 infected systems, while additional operations across multiple countries led to arrests, interrogations, searches, and server seizures. Investigators also identified a key suspect allegedly linked to 69 million euros in cryptocurrency proceeds, and separate reporting and research highlighted scrutiny of a SmokeLoader actor targeted as part of the crackdown.

Share:
Operation Endgame Disrupts IcedID, SmokeLoader, Trickbot and Other Malware Botnets
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 22, 20258mo ago

Analyst1 profiles a SmokeLoader actor targeted by Operation Endgame

Analyst1 published research examining the life and personality of a SmokeLoader actor said to have been targeted by Operation Endgame. The report added attribution-focused detail around one of the individuals linked to the disrupted malware ecosystem.

May 30, 20242y ago

Investigators identify key suspect tied to €69 million in crypto

Authorities said they had identified a main suspect allegedly connected to 69 million euros in cryptocurrency earnings from the criminal activity. They stated that the assets would be seized as soon as possible.

Authorities disinfect over 10,000 infected systems

As part of Operation Endgame, law enforcement and partners reported disinfecting more than 10,000 infected computers. The cleanup accompanied the broader disruption of malware delivery infrastructure used to enable ransomware and financial fraud.

Operation Endgame seizes servers and domains across multiple countries

Authorities, supported by Europol and Eurojust, took down more than 100 servers and seized over 2,000 domains during the operation. Additional police actions in several countries included arrests, interrogations, searches, and server seizures.

International Operation Endgame disrupts major malware botnets

An international law enforcement action dubbed Operation Endgame targeted criminal infrastructure tied to IcedID, SmokeLoader, SystemBC, Pikabot, Trickbot, and remnants of Bumblebee. The operation was described as the largest coordinated action to date against malware botnets and their supporting infrastructure.

Authorities identify millions of botnet-infected systems worldwide

Investigators reported that several million infected computers linked to the targeted malware ecosystems had been identified worldwide over the prior year. The infections were associated with botnets including IcedID, SmokeLoader, SystemBC, Pikabot, Trickbot, and Bumblebee remnants.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.