Skip to main content
Back to the takedown index

Operation Endgame

Operation Endgame wave 3

November 2025, Multi threat campaign

Verified core entry, last reviewed August 21, 2026

What was taken down?

More than 1,000 servers disrupted; approximately 20 domains seized; access to several hundred thousand infected machines removed from operators.[1]

See what happened

What happened to the people?

Officials reported 1 apprehended.
Group accounted for: Partial

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

Third Endgame wave targeting infostealer and remote-access-trojan infrastructure, with a principal VenomRAT suspect arrested in Greece.[1]

Announced November 14, 2025.

Date
November 10 to November 14, 2025
Target
Rhadamanthys, VenomRAT, Elysium botnet, infostealer and rat infrastructure
Activity
Multi threat campaign, Malware and botnets, Fraud and stolen data
Operational lead
Not established
Partners
Europol, Hellenic Police[1]
Jurisdiction
Germany, Netherlands, France, Greece, United Kingdom, United States, and European Union
Outcome
More than 1,000 servers disrupted; approximately 20 domains seized; access to several hundred thousand infected machines removed from operators.
Status
Completed
Legal mechanism
National judicial orders; European Arrest Warrant; Europol and Eurojust coordination
Group accounted for
Partial

Infrastructure

1,000 servers disabled and 20 domains seized.

more than 1,000
servers disabled
approximately 20
domains seized
Identifier Recorded as Status Notes
Not published more than 1,000 servers Disabled More than 1,000 servers disrupted.[1]
Not published approximately 20 domains Seized Approximately 20 domains seized.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

One principal suspect was arrested; the Rhadamanthys and Elysium operator groups were not publicly accounted for.

Multiple distinct malware operations targeted.

See the organizations and roles behind this action

Prosecutions ongoing as of the cutoff.[1]

Not established in the public record. No later activity is recorded against this entry.

Return class G. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Europol release on the November 2025 Operation Endgame action against Rhadamanthys, VenomRAT and Elysium

    Europol, November 14, 2025, Source grade P2

    Wave 3 infrastructure figures and the Greek arrest

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
  • SUPPORTING-SOURCE GAP. Only the international coordinator release was located in this pass; a second participating national authority release should be added.
  • VenomRAT suspect arrested in Greece on 2025-11-03, before the main action window.