Skip to main content
Back to the takedown index

Coreflood botnet disruption

April 2011, Malware and botnets
Led by United States Department of Justice, Federal Bureau of Investigation

Extended pass entry, last reviewed August 21, 2026

What was taken down?

US authorities seized Coreflood's command-and-control servers and a set of associated domains, then used civil/criminal process to substitute law-enforcement-controlled servers that instructed infected machines to stop the malware.

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not applicable

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

DOJ/FBI used a civil complaint, criminal seizure warrants for command servers, and a temporary restraining order to seize and disable the Coreflood botnet, which had been used for banking and identity fraud.

Date
April 2011
Target
Coreflood, botnet
Activity
Malware and botnets
Operational lead
DOJ and FBI
Jurisdiction
Not established
Outcome
US authorities seized Coreflood's command-and-control servers and a set of associated domains, then used civil/criminal process to substitute law-enforcement-controlled servers that instructed infected machines to stop the malware.
Status
Completed
Legal mechanism
Civil complaint; criminal seizure warrants; temporary restraining order and injunctive relief (D. Conn.)
Group accounted for
Not applicable

Infrastructure

29 domains seized.

approximately 29
domains seized
Identifier Recorded as Status Notes
Not published approximately 29 domains Seized, United States Domains associated with Coreflood C2 infrastructure named in the seizure warrant.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not applicable

No individual operator was publicly charged in the seizure action itself; the case proceeded as an infrastructure-disruption operation.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Coreflood botnet disruption case history

    US DOJ, April 13, 2011, Source grade S2

    Establishes the civil/criminal seizure of Coreflood command infrastructure and use of a TRO/injunction to disable the botnet.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass (reports covering ~75-78 worldwide incidents). Not independently re-verified source-by-source in the same manner as the original 38-incident core; source_quality is capped at S2/P2 pending a dedicated verification pass, per the project's own recommended-next-steps methodology.