Skip to main content
Back to the takedown index

3ve ad-fraud botnet disruption

November 2018, Malware and botnets
Led by Federal Bureau of Investigation

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Botnet C2 and fraudulent ad-traffic infrastructure disrupted; sinkholing conducted with private-sector partners.

See what happened

What happened to the people?

Officials reported 8 charged.
Group accounted for: Partial

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

DOJ/FBI, working with a coalition of technology and security companies including Google, White Ops, and others, disrupted the 3ve digital-advertising-fraud botnet and unsealed related indictments.

Date
November 2018
Target
3ve ("Eve"), ad fraud botnet
Activity
Malware and botnets
Operational lead
FBI
Partners
Google[1]
Jurisdiction
Not established
Outcome
Botnet C2 and fraudulent ad-traffic infrastructure disrupted; sinkholing conducted with private-sector partners.
Status
Completed
Legal mechanism
Federal indictment; coordinated technical sinkholing operation.
Group accounted for
Partial

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

The cited record does not say how large the group was or whether everyone involved has been identified.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Nine charged in $36 million digital advertising fraud scheme (3ve/Methbot)

    US DOJ / FBI, November 27, 2018, Source grade P1

    Establishes the 3ve ad-fraud botnet disruption and associated indictment.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.