Organizations and roles
Last reviewed August 21, 2026
The public record puts 5 organizations on this action. Operational lead: Microsoft DCU and DOJ. The table lists the role the cited record assigns each one, in the record's own wording where it gives any.
Why this page names organizations only
Roles on this page describe the agencies that took part. Individuals named in the public record appear on the takedown entry itself, under People and accountability.
Organizations and roles
| Emblem | Organization | Role | What the record says |
|---|---|---|---|
| Microsoft Digital Crimes Unit United States , United States | Co-lead | Obtained the civil court order and seized or sinkholed approximately 2,300 domains. | |
| United States Department of Justice United States , United States | Co-lead | Seized the central command structure and the marketplaces selling the malware. | |
| European Cybercrime Centre | Coordinator | Facilitated suspension of locally based infrastructure in Europe. | |
| Cloudflare United States , United States | Technical partner | Blocked and disabled associated infrastructure. | |
| Japan Cybercrime Control Center Japan , Japan | Supporting | Facilitated suspension of Japan-based infrastructure. |
Accountability
Legal authority
US civil court order (Northern District of Georgia) plus DOJ criminal seizure process; Europol EC3 and Japan JC3 coordination
Ongoing investigation
Group accounted for: Partial. No arrests or charges accompanied the action, the developer was not apprehended, and the service resumed operating within days.
This page records organizational involvement as the cited sources state it. Where a role carries no description, the record gives none.
Last reviewed August 21, 2026