[Back to the takedown index](https://takedownindex.org/takedowns)

[Operation Endgame](https://takedownindex.org/takedowns/operation-endgame)

# Operation Endgame wave 2

May 2025, Multi threat campaign
Led by [Bundeskriminalamt](https://takedownindex.org/organizations/bundeskriminalamt)

Verified core entry, last reviewed August 21, 2026

What was taken down?

Approximately 300 servers disrupted worldwide; roughly 650 domains neutralized; approximately 3.5 million EUR in cryptocurrency seized during the wave.[[1]](#source-1)[[2]](#source-2)[[4]](#source-4)

[See what happened](#what-happened)

What happened to the people?

Officials reported 20 charged.
3 charged and 1 publicly wanted named in the public record.
Group accounted for: Members remain at large

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

Second Endgame wave targeting initial-access malware and loaders, combining infrastructure seizure with a large set of criminal charges including the DanaBot indictment and the Qakbot administrator.[[1]](#source-1)[[2]](#source-2)[[4]](#source-4)

Announced May 23, 2025.

**Date:** May 19 to May 22, 2025

**Target:** DanaBot, Bumblebee, Lactrodectus, Qakbot, HijackLoader, Trickbot, Warmcookie, malware dropper ecosystem

**Activity:** Multi threat campaign, Malware and botnets, Ransomware, Fraud and stolen data

**Operational lead:** BKA

**Partners**

Europol, USAO-CDCA[[1]](#source-1)[[2]](#source-2)[[4]](#source-4)

- [European Union Agency for Law Enforcement Cooperation](https://takedownindex.org/organizations/european-union-agency-for-law-enforcement-cooperation), coordinator
- [United States Attorney's Office for the Central District of California](https://takedownindex.org/organizations/united-states-attorney-s-office-for-the-central-district-of-california), charging

**Jurisdiction:** Germany, Netherlands, France, Denmark, United Kingdom, United States, and Canada

**Outcome:** Approximately 300 servers disrupted worldwide; roughly 650 domains neutralized; approximately 3.5 million EUR in cryptocurrency seized during the wave.

**Status:** Completed

**Legal mechanism:** National judicial orders across participating states; US indictments (Central District of California and others); Europol and Eurojust coordination

**Group accounted for:** Members remain at large

### Infrastructure

300 servers disabled and 650 domains seized.

| Identifier | Recorded as | Status | Notes |
| --- | --- | --- | --- |
| Not published | approximately 300 servers | Disabled | Approximately 300 servers disrupted worldwide.[[4]](#source-4) |
| Not published | approximately 650 domains | Seized | Approximately 650 domains neutralized.[[4]](#source-4) |

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

## People and accountability

Named in the public record: 3 charged and 1 publicly wanted.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Reported and named. Officials reported 20 charged. 3 charged and 1 publicly wanted named in the public record. The two figures come from different places and are never added together. Officials publish a headline total, and this index counts only the individuals it can name from the cited record.

#### Aleksandr Stepanov

Lead defendant, DanaBot malware scheme. Current public status: Charged.

**Charging authority:** United States Attorney's Office for the Central District of California

**Main charges:** Not established in the public record

**Case number:** Not established in the public record

**Arresting authority:** Not established in the public record

**Arrest location:** Not established in the public record

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[3]](#source-3)

**Full record:** [Everything indexed for Aleksandr Stepanov](https://takedownindex.org/people/aleksandr-stepanov)

#### Artem Aleksandrovich Kalinkin

Lead defendant, DanaBot malware scheme. Current public status: Charged.

**Charging authority:** United States Attorney's Office for the Central District of California

**Main charges:** Not established in the public record

**Case number:** Not established in the public record

**Arresting authority:** Not established in the public record

**Arrest location:** Not established in the public record

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[3]](#source-3)

**Full record:** [Everything indexed for Artem Aleksandrovich Kalinkin](https://takedownindex.org/people/artem-aleksandrovich-kalinkin)

#### Rustam Rafailevich Gallyamov

Leader and developer of the Qakbot botnet. Current public status: Charged and Publicly wanted.

**Charging authority:** United States Attorney's Office for the Central District of California

**Main charges:** Conspiracy to commit computer fraud

**Case number:** Not established in the public record

**Arresting authority:** Not established in the public record

**Arrest location:** Not established in the public record

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[1]](#source-1)

**Full record:** [Everything indexed for Rustam Rafailevich Gallyamov](https://takedownindex.org/people/rustam-rafailevich-gallyamov)

Group accounted for: Members remain at large

Authorities announced international targets who remained at large, and the DanaBot defendants were largely charged in absentia.

Multiple distinct malware crews targeted in one wave.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/operation-endgame-wave-2/organizations)

## What happened afterward

Prosecutions ongoing; cumulative Endgame cryptocurrency seizures reported at approximately 21.2 million EUR.[[1]](#source-1)[[2]](#source-2)[[4]](#source-4)

Not established in the public record. No later activity is recorded against this entry.

Return class G. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. [How this index handles it](https://takedownindex.org/about).

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[US Department of Justice announcement charging the alleged Qakbot leader and seizing cryptocurrency](https://takedownindex.org/sources/united-states-department-of-justice-us-department-of-justice-announcement-chargi)

United States Department of Justice, May 22, 2025, Source grade P1

Gallyamov charge, continued operation after the 2023 takedown

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

2.
[United States v. Aleksandr Stepanov et al., DanaBot indictment](https://takedownindex.org/sources/united-states-district-court-for-the-central-district-of-california-united-state)

United States District Court for the Central District of California, May 22, 2025, Source grade P0

16-defendant DanaBot charges announced with the Endgame wave

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

3.
[16 defendants federally charged in connection with DanaBot malware scheme](https://takedownindex.org/sources/usao-central-district-of-california-16-defendants-federally-charged-in-connectio)

USAO Central District of California, May 22, 2025, Source grade P1

Names lead defendants Aleksandr Stepanov ('JimmBee') and Artem Kalinkin ('Onix') among 16 charged in the DanaBot scheme (part of Operation Endgame wave 2).

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

4.
[Europol release on Operation Endgame's 2025 action against initial access malware](https://takedownindex.org/sources/europol-europol-release-on-operation-endgame-s-2025-action-against-initial-acces)

Europol, May 23, 2025, Source grade P2

Wave 2 infrastructure figures, charges, cryptocurrency seizures

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
- The DanaBot indictment names 16 defendants, most believed to be in Russia. Only Gallyamov is carried as a named person record in this pass; the remaining DanaBot defendants are a documented gap.
- Reported charged count of 20 is an official aggregate and is not equal to the number of named person records.

Research context

## How this entry was checked

This entry went through a dedicated source verification pass. Publisher, title, publication date, and docket numbers were confirmed against each cited source.

Source review: Verified core

Sources cited: 4

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Operation Deep Sentinel](https://takedownindex.org/takedowns/operation-deep-sentinel)
- [Operation Stream / Kidflix](https://takedownindex.org/takedowns/operation-stream-kidflix)
- [Radar/Dispossessor ransomware disruption](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
