Category

# Botnet and malware takedowns

Actions against the infrastructure that runs malware: the command and control servers, the domains that reach them, and the networks of infected machines they steer.

Records 19 2011 to 2026

Infrastructure 17 Items recorded as acted on

People named 13 Distinct people in these records

Sources 31 Cited across the category

## What this category covers

Seizures of command and control infrastructure, sinkholing that redirects infected machines to controlled servers, court authorised remote remediation, and the arrests and charges brought alongside them.

Every entry below is an action that was carried out, not an announcement of intent. The [counting rules](https://takedownindex.org/about/counting-incidents) and the [inclusion definition](https://takedownindex.org/about/what-counts) apply to this category exactly as they apply to the rest of the index.

What the record does not settle

- 4 of 19 records have a documented successor. Silence in the other rows is not evidence that a service stayed down.
- 2 records carry no established start date.
- Reported figures come from the acting authorities. Named figures come from people recorded individually here. The two are never added together.

## Chronology

| Date | Takedown | Target | Led by | Jurisdictions |
| --- | --- | --- | --- | --- |
| Apr 13, 2011 | [Coreflood botnet disruption](https://takedownindex.org/takedowns/coreflood-botnet-disruption) | Coreflood | DOJ and FBI | Not established |
| Nov 8, 2011 | [Operation Ghost Click](https://takedownindex.org/takedowns/operation-ghost-click) | DNSChanger | FBI | Not established |
| Jun 5, 2013 | [Citadel botnet disruption](https://takedownindex.org/takedowns/citadel-botnet-disruption) | Citadel | FBI | Not established |
| Dec 5, 2013 | [ZeroAccess botnet disruption](https://takedownindex.org/takedowns/zeroaccess-botnet-disruption) | ZeroAccess | FBI | Not established |
| May 30, 2014 | [Operation Tovar](https://takedownindex.org/takedowns/operation-tovar) | Gameover Zeus botnet and CryptoLocker ransomware | FBI and NCA | International |
| Feb 24, 2015 | [Ramnit botnet disruption](https://takedownindex.org/takedowns/ramnit-botnet-disruption) | Ramnit | Not established | Not established |
| Apr 8, 2015 | [Operation Source / Beebone botnet disruption](https://takedownindex.org/takedowns/operation-source-beebone-botnet-disruption) | Beebone | Dutch National Police | Not established |
| Apr 9, 2015 | [Simda botnet disruption](https://takedownindex.org/takedowns/simda-botnet-disruption) | Simda | Not established | Not established |
| Oct 13, 2015 | [Dridex/Bugat/Cridex disruption](https://takedownindex.org/takedowns/dridex-bugat-cridex-disruption) | Dridex (also known as Bugat/Cridex) | FBI and NCA | Not established |
| Nov 27, 2018 | [3ve ad-fraud botnet disruption](https://takedownindex.org/takedowns/3ve-ad-fraud-botnet-disruption) | 3ve ("Eve") | FBI | Not established |
| Jan 26, 2021 | [Operation Ladybird](https://takedownindex.org/takedowns/operation-ladybird) | Emotet | Dutch National Police and BKA | International |
| Aug 25, 2023 | [Operation Duck Hunt](https://takedownindex.org/takedowns/operation-duck-hunt) | Qakbot | FBI | International |
| Nov 1, 2023 | [IPStorm botnet dismantlement](https://takedownindex.org/takedowns/ipstorm-botnet-dismantlement) | IPStorm | FBI | Not established |
| May 24, 2024 | [911 S5 botnet dismantlement](https://takedownindex.org/takedowns/911-s5-botnet-dismantlement) | 911 S5 | FBI | International |
| Oct 28, 2024 | [Operation Magnus (RedLine and META infostealers)](https://takedownindex.org/takedowns/operation-magnus-redline-and-meta-infostealers) | RedLine Stealer and META Stealer | Dutch National Police | Not established |
| May 13, 2025 | [Lumma Stealer disruption](https://takedownindex.org/takedowns/lumma-stealer-disruption) | Lumma Stealer | Microsoft DCU and DOJ | International |
| Mar 19, 2026 | [Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption](https://takedownindex.org/takedowns/aisuru-kimwolf-jackskid-mossad-iot-ddos-botnet-disruption) | Aisuru, KimWolf, JackSkid, and Mossad IoT DDoS botnets | USAO-AK and FBI | Not established |
| Date not established | [FluBot disruption](https://takedownindex.org/takedowns/flubot-disruption) | FluBot | Dutch National Police | Not established |
| January 2025 | [INTERPOL Operation Secure](https://takedownindex.org/takedowns/interpol-operation-secure) | Infostealer malware infrastructure (26-country action) | INTERPOL | Not established |

## Who leads these actions

- [FBI](https://takedownindex.org/organizations/federal-bureau-of-investigation)11 records
- [Dutch National Police](https://takedownindex.org/organizations/politie-netherlands-national-police)4 records
- [NCA](https://takedownindex.org/organizations/national-crime-agency)2 records
- [DOJ](https://takedownindex.org/organizations/united-states-department-of-justice)2 records
- [BKA](https://takedownindex.org/organizations/bundeskriminalamt)1 record
- [INTERPOL](https://takedownindex.org/organizations/international-criminal-police-organization)1 record
- [Microsoft DCU](https://takedownindex.org/organizations/microsoft-digital-crimes-unit)1 record
- [USAO-AK](https://takedownindex.org/organizations/united-states-attorney-s-office-for-the-district-of-alaska)1 record

## Where they were carried out

- United States5 records
- Germany4 records
- European Union3 records
- United Kingdom3 records
- Netherlands3 records
- France2 records
- Ukraine2 records
- Canada1 record

A takedown is counted once for every country named in its geographic scope, so these figures sum to more than 19.

[Filter the full index by this category](https://takedownindex.org/takedowns?activity_type=botnet_malware)
