[Back to the takedown index](https://takedownindex.org/takedowns)

# 911 S5 botnet dismantlement

May 2024, Malware and botnets
Led by [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation)

Verified core entry, last reviewed August 21, 2026

What was taken down?

23 domains and more than 70 servers seized; botnet infrastructure dismantled; approximately 30 million USD in assets seized or restrained.[[1]](#source-1)[[2]](#source-2)

[See what happened](#what-happened)

What happened to the people?

Officials reported 1 charged and 1 apprehended.
1 charged and 1 apprehended named in the public record.
Group accounted for: Likely complete

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

US-led international operation dismantling the 911 S5 residential proxy botnet, described by the FBI Director as likely the world's largest botnet, with the administrator arrested in Singapore.[[1]](#source-1)[[2]](#source-2)

Announced May 29, 2024.

**Date:** May 24 to May 29, 2024

**Target:** 911 S5, residential proxy botnet

**Activity:** Malware and botnets, Criminal hosting and proxies, Fraud and stolen data

**Operational lead:** FBI

**Partners**

DCIS, SPF, and 1 more[[1]](#source-1)[[2]](#source-2)

- [Defense Criminal Investigative Service](https://takedownindex.org/organizations/defense-criminal-investigative-service), investigating
- [Singapore Police Force](https://takedownindex.org/organizations/singapore-police-force), arresting
- [Office of Foreign Assets Control, United States Department of the Treasury](https://takedownindex.org/organizations/office-of-foreign-assets-control-united-states-department-of-the-treasury), other

**Jurisdiction:** United States, Singapore, Thailand, and Germany

**Outcome:** 23 domains and more than 70 servers seized; botnet infrastructure dismantled; approximately 30 million USD in assets seized or restrained.

**Status:** Completed

**Legal mechanism:** US seizure warrants and criminal charges; Singapore, Thai, and German judicial cooperation

**Group accounted for:** Likely complete

### Infrastructure

23 domains seized, 70 servers seized, and 19,000,000 IP addresses disabled.

| Identifier | Recorded as | Status | Notes |
| --- | --- | --- | --- |
| Not published | 23 domains | Seized | 23 domains seized as part of the dismantlement.[[2]](#source-2) |
| Not published | more than 70 servers | Seized | More than 70 servers seized.[[2]](#source-2) |
| Not published | more than 19,000,000 IP addresses | Disabled | More than 19 million unique IP addresses were compromised and used as proxies, including 613,841 in the United States.[[2]](#source-2) |

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

## People and accountability

Named in the public record: 1 charged and 1 apprehended.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Reported and named. Officials reported 1 charged and 1 apprehended. 1 charged and 1 apprehended named in the public record. The two figures come from different places and are never added together. Officials publish a headline total, and this index counts only the individuals it can name from the cited record.

#### YunHe Wang

Administrator of the 911 S5 residential proxy botnet. Current public status: Arrested, Sanctioned, and Charged.

**Charging authority:** United States Department of Justice

**Main charges:** Conspiracy to commit computer fraud; Substantive computer fraud; Conspiracy to commit wire fraud; Conspiracy to commit money laundering

**Case number:** Not established in the public record

**Arresting authority:** Singapore Police Force

**Arrest location:** Singapore

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[1]](#source-1)[[2]](#source-2)

**Full record:** [Everything indexed for YunHe Wang](https://takedownindex.org/people/yunhe-wang)

Group accounted for: Likely complete

The principal administrator was arrested and the infrastructure dismantled. Associates were designated under sanctions rather than criminally charged, so the criminal roster is not formally closed.

One principal administrator charged; several associates named in the parallel sanctions action rather than in criminal charges.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/911-s5-botnet-dismantlement/organizations)

## What happened afterward

YunHe Wang arrested and prosecuted; OFAC sanctioned Wang, associates, and three Thai entities separately.[[1]](#source-1)[[2]](#source-2)

Not established in the public record. No later activity is recorded against this entry.

Return class G. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. [How this index handles it](https://takedownindex.org/about).

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[Treasury Sanctions Actors Behind the 911 S5 Botnet](https://takedownindex.org/sources/united-states-department-of-the-treasury-treasury-sanctions-actors-behind-the-91)

United States Department of the Treasury, May 28, 2024, Source grade P2

Sanctions designations of Wang, associates, and three Thai entities

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

2.
[911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation](https://takedownindex.org/sources/united-states-department-of-justice-911-s5-botnet-dismantled-and-its-administrat)

United States Department of Justice, May 29, 2024, Source grade P1

Arrest of YunHe Wang, domain and server seizures, 19 million compromised IP addresses including 613,841 in the United States

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
- Official figure: more than 19 million unique IP addresses compromised, including 613,841 in the United States.
- Linked to approximately 5.9 billion USD in pandemic-relief fraud losses, a victim-side figure.
- Sanctions designations are recorded separately and are not counted as criminal charges.

Research context

## How this entry was checked

This entry went through a dedicated source verification pass. Publisher, title, publication date, and docket numbers were confirmed against each cited source.

Source review: Verified core

Sources cited: 2

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [BreachForums domain seizure](https://takedownindex.org/takedowns/breachforums-domain-seizure)
- [Samourai Wallet seizure](https://takedownindex.org/takedowns/samourai-wallet-seizure)
- [Radar/Dispossessor ransomware disruption](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
