{"table":"resurgences","columns":["reference_id","takedown_reference_id","takedown_slug","subsequent_takedown_reference_id","subsequent_takedown_slug","name","relationship","resurgence_class","first_seen_on","domains","onion_addresses","other_infrastructure","subsequently_seized","confidence","continuity_evidence","notes"],"row_count":25,"research_cutoff_on":"2026-08-21","generated_on":"2026-08-21","terms":"Free to reuse with attribution to the Internet Takedown Index. A research aggregation of public reporting, not a legal reference.","rows":[{"reference_id":"res_silk_road_2","takedown_reference_id":"td_2013_silk_road","takedown_slug":"silk-road-seizure","subsequent_takedown_reference_id":"td_2014_operation_onymous","subsequent_takedown_slug":"operation-onymous","name":"Silk Road 2.0","relationship":"rebrand","resurgence_class":"C","first_seen_on":"2013-11-06","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"high","continuity_evidence":"Launched approximately five weeks after the original seizure by former Silk Road staff and administrators, explicitly adopting the brand, forum community, and site design. Established in SDNY charging documents.","notes":["Brand and community continuity are strong; the founding operator was different. Classified C rather than A."]},{"reference_id":"res_silk_road_ecosystem","takedown_reference_id":"td_2013_silk_road","takedown_slug":"silk-road-seizure","subsequent_takedown_reference_id":"td_2017_alphabay","subsequent_takedown_slug":"alphabay-seizure","name":"AlphaBay and successor market ecosystem","relationship":"ecosystem_successor","resurgence_class":"E","first_seen_on":"2014-12-01","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"high","continuity_evidence":"Vendor and buyer populations migrated to successor markets. No operator, code, or infrastructure continuity with Silk Road.","notes":["Ecosystem replacement, explicitly not the same entity."]},{"reference_id":"res_alphabay_ecosystem","takedown_reference_id":"td_2017_alphabay","takedown_slug":"alphabay-seizure","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"Post-AlphaBay market ecosystem","relationship":"ecosystem_successor","resurgence_class":"E","first_seen_on":"2017-07-20","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"medium","continuity_evidence":"Users migrated to Dream Market and other venues, which was the intended effect of the parallel Hansa operation.","notes":["A service using the AlphaBay name reappeared in 2021 under an alleged former staff member. Not verified to the A/B/C standard in this pass; recorded as a coverage gap."]},{"reference_id":"res_hydra_ecosystem","takedown_reference_id":"td_2022_hydra","takedown_slug":"hydra-market-server-seizure","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"Mega, Blacksprut, Kraken, OMG!OMG!, Solaris","relationship":"ecosystem_successor","resurgence_class":"E","first_seen_on":"2022-04-01","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"medium","continuity_evidence":"Multiple Russian-language markets absorbed Hydra's vendor and buyer base after the seizure. No verified operator continuity with Hydra's administration.","notes":["Explicitly not classified as a rebrand. These are competing successors, not the same entity."]},{"reference_id":"res_raidforums_breachforums","takedown_reference_id":"td_2022_raidforums","takedown_slug":"operation-tourniquet","subsequent_takedown_reference_id":"td_2023_breachforums","subsequent_takedown_slug":"breachforums-shutdown-following-administrator-arrest","name":"BreachForums","relationship":"ecosystem_successor","resurgence_class":"C","first_seen_on":"2022-03-04","domains":["breachforums.is"],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"high","continuity_evidence":"Launched by a different individual explicitly as a replacement for RaidForums, inheriting its user community, structure, and function. Operator continuity with RaidForums administration is not established.","notes":["Classified C on brand-and-function succession, not operator continuity. Founded before the RaidForums domain seizure but after the administrator's arrest."]},{"reference_id":"res_breachforums_2023_2024","takedown_reference_id":"td_2023_breachforums","takedown_slug":"breachforums-shutdown-following-administrator-arrest","subsequent_takedown_reference_id":"td_2024_breachforums","subsequent_takedown_slug":"breachforums-domain-seizure","name":"BreachForums under ShinyHunters and Baphomet","relationship":"partial_operator_continuity","resurgence_class":"A","first_seen_on":"2023-06-01","domains":["breachforums.st"],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"medium","continuity_evidence":"Reconstituted by individuals who had served as staff on the prior iteration, retaining brand, database, and community.","notes":["Operator continuity is asserted through handles rather than confirmed legal identities."]},{"reference_id":"res_breachforums_2024_2025","takedown_reference_id":"td_2024_breachforums","takedown_slug":"breachforums-domain-seizure","subsequent_takedown_reference_id":"td_2025_breachforums","subsequent_takedown_slug":"breachforums-portal-seizure-2025","name":"BreachForums subsequent iterations","relationship":"partial_operator_continuity","resurgence_class":"B","first_seen_on":"2024-06-01","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"low","continuity_evidence":"The forum repeatedly returned on new infrastructure under overlapping staff handles and was seized again.","notes":["Confidence is low because the 2025 seizure record itself has a material source gap."]},{"reference_id":"res_gameover_zeus_variant","takedown_reference_id":"td_2014_gameover_zeus","takedown_slug":"operation-tovar","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"Gameover Zeus DGA variant","relationship":"same_service_new_infrastructure","resurgence_class":"B","first_seen_on":"2014-07-10","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":false,"confidence":"high","continuity_evidence":"A variant using the same codebase with a modified distribution mechanism appeared within approximately six weeks of the disruption, documented by multiple independent technical vendors.","notes":["Code continuity is strong. Operator continuity is inferred from the code lineage rather than officially attributed."]},{"reference_id":"res_emotet_return","takedown_reference_id":"td_2021_emotet","takedown_slug":"operation-ladybird","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"Emotet resurgence","relationship":"same_service_new_infrastructure","resurgence_class":"B","first_seen_on":"2021-11-14","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":false,"confidence":"high","continuity_evidence":"Emotet returned on new infrastructure roughly ten months after the takedown, rebuilt with assistance from the Trickbot operation and documented by multiple independent technical vendors.","notes":["One of the clearest documented cases of a botnet surviving a full infrastructure takeover."]},{"reference_id":"res_qakbot_return","takedown_reference_id":"td_2023_qakbot","takedown_slug":"operation-duck-hunt","subsequent_takedown_reference_id":"td_2025_endgame_w2","subsequent_takedown_slug":"operation-endgame-wave-2","name":"Qakbot continued operation","relationship":"same_operators","resurgence_class":"C","first_seen_on":"2023-12-01","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"high","continuity_evidence":"DOJ charging documents state that the alleged leader continued malware operations after the 2023 takedown, establishing operator continuity by official attribution.","notes":["Official attribution satisfies the A/B/C evidentiary standard."]},{"reference_id":"res_hive_hunters","takedown_reference_id":"td_2023_hive","takedown_slug":"hive-ransomware-infiltration-and-seizure","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"Hunters International","relationship":"rebrand","resurgence_class":"C","first_seen_on":"2023-10-01","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":false,"confidence":"medium","continuity_evidence":"Multiple independent technical analyses reported substantial code overlap with the Hive encryptor. The successor group publicly stated it purchased the source code rather than being a rebrand of the same operators.","notes":["DISPUTED. Code continuity is well supported; operator continuity is contested by the group's own claim. Not elevated to A."]},{"reference_id":"res_lockbit_relaunch","takedown_reference_id":"td_2024_cronos_w1","takedown_slug":"operation-cronos-wave-1","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"LockBit relaunch and LockBit 4.0 and 5.0","relationship":"same_operators","resurgence_class":"B","first_seen_on":"2024-02-24","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":false,"confidence":"high","continuity_evidence":"The administrator publicly relaunched a new leak site within five days of the takedown, attributing the compromise to an unpatched PHP vulnerability. Subsequent versions 4.0 and 5.0 were released under the same brand and administrator identity.","notes":["Post-takedown victim listings are widely assessed as inflated with recycled claims, with one analysis finding roughly 68 percent were reposts. Recorded as a source disagreement.","A May 2025 compromise of the group's own panel was carried out by an unknown actor, not by law enforcement, and is not recorded as a takedown.","A claimed LockBit, Qilin, and DragonForce alliance in late 2025 is unconfirmed and likely promotional."]},{"reference_id":"res_lumma_rebound","takedown_reference_id":"td_2025_lumma","takedown_slug":"lumma-stealer-disruption","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"Lumma Stealer rebound","relationship":"same_service_new_infrastructure","resurgence_class":"B","first_seen_on":"2025-05-26","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":false,"confidence":"medium","continuity_evidence":"Indicators associated with the operation reappeared within days of the seizure and the developer publicly acknowledged the disruption while continuing to operate.","notes":["Illustrates the limits of domain seizure without arrests."]},{"reference_id":"res_webstresser_ecosystem","takedown_reference_id":"td_2018_webstresser","takedown_slug":"webstresser-org-takedown","subsequent_takedown_reference_id":"td_2022_poweroff_dec","subsequent_takedown_slug":"operation-poweroff-december-2022-wave","name":"Replacement booter and stresser services","relationship":"ecosystem_successor","resurgence_class":"E","first_seen_on":"2018-05-01","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"high","continuity_evidence":"The DDoS-for-hire market was repopulated by unrelated operators, prompting the recurring PowerOFF wave structure.","notes":["This ecosystem pattern is the reason PowerOFF is modeled as a recurring umbrella campaign."]},{"reference_id":"res_snake_none","takedown_reference_id":"td_2023_snake","takedown_slug":"operation-medusa","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"No documented return","relationship":"unknown","resurgence_class":"F","first_seen_on":null,"domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"medium","continuity_evidence":"No affirmative evidence of a Snake network reconstitution was found through the research cutoff. US officials expressed confidence the network could not be readily rebuilt.","notes":["F means no affirmative evidence of return was found, not that return was impossible."]},{"reference_id":"res_anom_none","takedown_reference_id":"td_2021_anom","takedown_slug":"operation-trojan-shield","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"No documented return","relationship":"unknown","resurgence_class":"F","first_seen_on":null,"domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"high","continuity_evidence":"The platform was law-enforcement-operated from inception and had no criminal operator to reconstitute it.","notes":[]},{"reference_id":"res_wtv_none","takedown_reference_id":"td_2019_welcome_to_video","takedown_slug":"welcome-to-video-seizure","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"No documented return","relationship":"unknown","resurgence_class":"F","first_seen_on":null,"domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"medium","continuity_evidence":"No affirmative evidence of a return of this specific service was found through the cutoff.","notes":["Successor CSAM services in the wider ecosystem are outside the scope of this record and are a known coverage gap."]},{"reference_id":"res_archetyp_none","takedown_reference_id":"td_2025_archetyp","takedown_slug":"operation-deep-sentinel","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"No documented return","relationship":"unknown","resurgence_class":"F","first_seen_on":null,"domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"medium","continuity_evidence":"No affirmative evidence of a return was found through the cutoff. The administrator had published a signed statement indicating the market would not return.","notes":[]},{"reference_id":"res_avalanche_none","takedown_reference_id":"td_2016_avalanche","takedown_slug":"avalanche-network-takedown","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"No documented return","relationship":"unknown","resurgence_class":"F","first_seen_on":null,"domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"medium","continuity_evidence":"No affirmative evidence of the Avalanche fast-flux infrastructure being reconstituted was found. The malware families it hosted continued independently.","notes":["Distinguish the hosting infrastructure, which did not return, from its criminal customers, which persisted."]},{"reference_id":"res_encrochat_none","takedown_reference_id":"td_2020_encrochat","takedown_slug":"encrochat-interception-and-shutdown","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"No documented return","relationship":"unknown","resurgence_class":"F","first_seen_on":null,"domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":null,"confidence":"medium","continuity_evidence":"The EncroChat service did not return. Users migrated to other encrypted platforms including Sky ECC, which was itself later targeted.","notes":[]},{"reference_id":"res_monopoly_to_spector","takedown_reference_id":"td_2021_monopoly_market","takedown_slug":"monopoly-market-seizure","subsequent_takedown_reference_id":"td_2023_operation_spector","subsequent_takedown_slug":"operation-spector","name":"Operation SpecTor vendor/buyer sweep","relationship":"same_operators","resurgence_class":"G","first_seen_on":"2023-05-02","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":false,"confidence":"medium","continuity_evidence":"SpecTor explicitly used evidence gathered during the covert Monopoly Market seizure to identify vendors and buyers for arrest.","notes":["Linkage is evidentiary/investigative rather than infrastructural resurgence in the usual sense."]},{"reference_id":"res_weleakinfo_to","takedown_reference_id":"td_2020_weleakinfo","takedown_slug":"weleakinfo-seizure","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"WeLeakInfo.to replacement service","relationship":"same_service_new_infrastructure","resurgence_class":"B","first_seen_on":"2020-02-01","domains":["weleakinfo.to"],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"high","continuity_evidence":"A replacement service using the same branding and service model appeared shortly after the original seizure; the replacement infrastructure was itself later seized by law enforcement.","notes":[]},{"reference_id":"res_alphv_reassert","takedown_reference_id":"td_2023_alphv_blackcat","takedown_slug":"alphv-blackcat-disruption","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"ALPHV/BlackCat infrastructure reassertion","relationship":"same_operators","resurgence_class":"B","first_seen_on":"2023-12-20","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":false,"confidence":"medium","continuity_evidence":"Group operators reasserted control of some leak-site infrastructure shortly after the FBI's technical disruption.","notes":[]},{"reference_id":"res_amaq_to_is_web_2019","takedown_reference_id":"td_2018_amaq","takedown_slug":"amaq-propaganda-infrastructure-takedown","subsequent_takedown_reference_id":"td_2019_is_web_infrastructure","subsequent_takedown_slug":"islamic-state-web-infrastructure-takedown","name":"Renewed Islamic State propaganda infrastructure","relationship":"same_service_new_infrastructure","resurgence_class":"B","first_seen_on":"2019-01-01","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"medium","continuity_evidence":"Islamic State rebuilt propaganda distribution infrastructure after the 2018 Amaq action, prompting the 2019 renewed operation.","notes":[]},{"reference_id":"res_lumma_rebound_domains","takedown_reference_id":"td_2025_lumma","takedown_slug":"lumma-stealer-disruption","subsequent_takedown_reference_id":null,"subsequent_takedown_slug":null,"name":"Lumma replacement domains (3 domains, seized same wave)","relationship":"same_operators","resurgence_class":"B","first_seen_on":"2025-05-14","domains":[],"onion_addresses":[],"other_infrastructure":[],"subsequently_seized":true,"confidence":"high","continuity_evidence":"Operators registered three replacement domains within approximately one day of the initial seizure; DOJ/Microsoft seized those as well within the same action window.","notes":[]}]}