Skip to main content

Category

State sponsored infrastructure takedowns

Actions against internet infrastructure attributed to state aligned groups.

Records 6 2018 to 2026
Infrastructure 7 Items recorded as acted on
People named 0 Distinct people in these records
Sources 9 Cited across the category

What this category covers

Attribution in these records reflects what the acting authorities stated publicly. It is carried as a sourced claim, not adopted here as settled fact.

Every entry below is an action that was carried out, not an announcement of intent. The counting rules and the inclusion definition apply to this category exactly as they apply to the rest of the index.

What the record does not settle

  • 1 of 6 records have a documented successor. Silence in the other rows is not evidence that a service stayed down.
  • Reported figures come from the acting authorities. Named figures come from people recorded individually here. The two are never added together.

Chronology

Date Takedown Target Led by Jurisdictions
May 23, 2018 VPNFilter botnet disruption VPNFilter (attributed to Russia-linked Sandworm) FBI Not established
Mar 18, 2022 Cyclops Blink disruption Cyclops Blink (attributed to Russia's GRU-linked Sandworm) FBI Not established
May 8, 2023 Operation MEDUSA Snake malware network FBI International
Dec 1, 2023 KV Botnet disruption KV Botnet FBI United States
Sep 1, 2024 Raptor Train botnet disruption Raptor Train FBI International
Apr 7, 2026 GRU DNS-hijacking router network disruption (APT28) GRU Military Unit 26165 SOHO router network FBI Not established

Who leads these actions

  • FBI 6 records

Where they were carried out

  • United States 3 records
  • Australia 1 record
  • Canada 1 record
  • France 1 record
  • United Kingdom 1 record
  • New Zealand 1 record

A takedown is counted once for every country named in its geographic scope, so these figures sum to more than 6.

Filter the full index by this category