Organizations and roles
Last reviewed August 21, 2026
The public record puts 5 organizations on this action. Operational lead: Dutch National Police and BKA. The table lists the role the cited record assigns each one, in the record's own wording where it gives any.
Why this page names organizations only
Roles on this page describe the agencies that took part. Individuals named in the public record appear on the takedown entry itself, under People and accountability.
Organizations and roles
| Emblem | Organization | Role | What the record says |
|---|---|---|---|
| Bundeskriminalamt Germany , Germany | Co-lead | Executed the German component of the infrastructure takeover. | |
| Politie (Netherlands National Police) Netherlands , Netherlands | Co-lead | Took control of the primary command-and-control infrastructure hosted in the Netherlands. | |
| European Union Agency for Law Enforcement Cooperation | Coordinator | Coordinated the eight-country operation and hosted the command post. | |
| European Union Agency for Criminal Justice Cooperation | Judicial cooperation | Supported judicial coordination. | |
| Cyberpolice Department of the National Police of Ukraine Ukraine , Ukraine | Arresting | Detained two individuals and raided infrastructure in Ukraine. |
Accountability
Legal authority
Judicial authorization across participating states including Dutch and German court process; US court authorization for the uninstall payload; EMPACT framework
Oversight
The record assigns prosecuting or judicial roles to Eurojust.
Ongoing investigation
Group accounted for: Partial. Two individuals were detained in Ukraine, but the malware returned within ten months, demonstrating that core operators remained active.
This page records organizational involvement as the cited sources state it. Where a role carries no description, the record gives none.
Last reviewed August 21, 2026