What was taken down?
More than 100 servers disrupted or taken down; more than 2,000 domains brought under law-enforcement control; 16 location searches.[1][2]
See what happenedWhat happened to the people?
Officials reported 8 charged, 4 apprehended, and 8 publicly wanted.
Group accounted for: Members remain at large
Did it stay down?
Not established in the public record. No later activity is recorded against this entry.
See what happened afterwardCoordinated action led by France, Germany, and the Netherlands against the dropper and loader ecosystem that feeds ransomware deployment, disrupting infrastructure for six malware families simultaneously.[1][2]
Announced May 30, 2024.
- Date
- May 27 to May 29, 2024
- Target
- IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, Trickbot, malware dropper ecosystem
- Activity
- Multi threat campaign, Malware and botnets, Ransomware
- Operational lead
- French Gendarmerie, BKA, and Dutch National Police
- Partners
- Europol, Eurojust[1]
- European Union Agency for Law Enforcement Cooperation , coordinator
- European Union Agency for Criminal Justice Cooperation , judicial cooperation
- Jurisdiction
- France, Germany, Netherlands, Denmark, United Kingdom, United States, Ukraine, Armenia, Portugal, Bulgaria, and Lithuania
- Outcome
- More than 100 servers disrupted or taken down; more than 2,000 domains brought under law-enforcement control; 16 location searches.
- Status
- Completed
- Legal mechanism
- National judicial orders in France, Germany, and the Netherlands; European Arrest Warrants; Europol and Eurojust coordination
- Group accounted for
- Members remain at large
Infrastructure
100 servers disabled and 2,000 domains seized.
- more than 100
- servers disabled
- more than 2,000
- domains seized
| Identifier | Recorded as | Status | Notes |
|---|---|---|---|
| Not published | more than 100 servers | Disabled | More than 100 servers taken down or disrupted across participating countries.[1] |
| Not published | more than 2,000 domains | Seized | More than 2,000 domains brought under law-enforcement control.[1] |
Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Members remain at large
German authorities explicitly published a wanted list of suspects who remained at large after the action, establishing remaining members by official statement.
Multiple independent malware crews were targeted; a single finite operator group is not a meaningful denominator for the wave as a whole.
Followed by wave 2 in May 2025 and wave 3 in November 2025; suspects added to the EU Most Wanted list.[1][2]
Not established in the public record. No later activity is recorded against this entry.
Return class B. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
Largest ever operation against botnets hits dropper malware ecosystem
Wave 1 infrastructure figures, initiating countries, arrests
-
[2]
Bundeskriminalamt statement and wanted list published for Operation Endgame
Named suspects remaining at large, German lead role
- One main suspect was alleged to have earned at least 69 million EUR in cryptocurrency.
- Arrests: one in Armenia and three in Ukraine, not publicly named in the announcement.
- Charged count reflects suspects publicly listed as wanted or charged by German authorities; the figure is contested across reporting and is not harmonized here.