Skip to main content

Category

Botnet and malware takedowns

Actions against the infrastructure that runs malware: the command and control servers, the domains that reach them, and the networks of infected machines they steer.

Records 19 2011 to 2026
Infrastructure 17 Items recorded as acted on
People named 13 Distinct people in these records
Sources 31 Cited across the category

What this category covers

Seizures of command and control infrastructure, sinkholing that redirects infected machines to controlled servers, court authorised remote remediation, and the arrests and charges brought alongside them.

Every entry below is an action that was carried out, not an announcement of intent. The counting rules and the inclusion definition apply to this category exactly as they apply to the rest of the index.

What the record does not settle

  • 4 of 19 records have a documented successor. Silence in the other rows is not evidence that a service stayed down.
  • 2 records carry no established start date.
  • Reported figures come from the acting authorities. Named figures come from people recorded individually here. The two are never added together.

Chronology

Date Takedown Target Led by Jurisdictions
Apr 13, 2011 Coreflood botnet disruption Coreflood DOJ and FBI Not established
Nov 8, 2011 Operation Ghost Click DNSChanger FBI Not established
Jun 5, 2013 Citadel botnet disruption Citadel FBI Not established
Dec 5, 2013 ZeroAccess botnet disruption ZeroAccess FBI Not established
May 30, 2014 Operation Tovar Gameover Zeus botnet and CryptoLocker ransomware FBI and NCA International
Feb 24, 2015 Ramnit botnet disruption Ramnit Not established Not established
Apr 8, 2015 Operation Source / Beebone botnet disruption Beebone Dutch National Police Not established
Apr 9, 2015 Simda botnet disruption Simda Not established Not established
Oct 13, 2015 Dridex/Bugat/Cridex disruption Dridex (also known as Bugat/Cridex) FBI and NCA Not established
Nov 27, 2018 3ve ad-fraud botnet disruption 3ve ("Eve") FBI Not established
Jan 26, 2021 Operation Ladybird Emotet Dutch National Police and BKA International
Aug 25, 2023 Operation Duck Hunt Qakbot FBI International
Nov 1, 2023 IPStorm botnet dismantlement IPStorm FBI Not established
May 24, 2024 911 S5 botnet dismantlement 911 S5 FBI International
Oct 28, 2024 Operation Magnus (RedLine and META infostealers) RedLine Stealer and META Stealer Dutch National Police Not established
May 13, 2025 Lumma Stealer disruption Lumma Stealer Microsoft DCU and DOJ International
Mar 19, 2026 Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption Aisuru, KimWolf, JackSkid, and Mossad IoT DDoS botnets USAO-AK and FBI Not established
Date not established FluBot disruption FluBot Dutch National Police Not established
January 2025 INTERPOL Operation Secure Infostealer malware infrastructure (26-country action) INTERPOL Not established

Who leads these actions

Where they were carried out

  • United States 5 records
  • Germany 4 records
  • European Union 3 records
  • United Kingdom 3 records
  • Netherlands 3 records
  • France 2 records
  • Ukraine 2 records
  • Canada 1 record

A takedown is counted once for every country named in its geographic scope, so these figures sum to more than 19.

Filter the full index by this category