Skip to main content
Back to the takedown index

Operation Magnus (RedLine and META infostealers)

October 2024, Malware and botnets
Led by Politie (Netherlands National Police)

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Servers seized; source code and backend databases obtained.

See what happened

What happened to the people?

1 charged named in the public record.
Group accounted for: Not established

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

Dutch-led Operation Magnus, coordinated with Eurojust, Europol, FBI, and other partners, took down the infrastructure of the RedLine and META infostealer malware families.

Date
October 2024
Target
RedLine Stealer and META Stealer, infostealer malware
Activity
Malware and botnets
Operational lead
Dutch National Police
Partners
Eurojust, FBI[1]
Jurisdiction
Not established
Outcome
Servers seized; source code and backend databases obtained.
Status
Completed
Legal mechanism
Dutch judicial search/seizure authority; coordinated international warrants.
Group accounted for
Not established

1
charged

Named in the public record: 1 charged.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Person Role Current public status
Alleged developer/administrator of RedLine Stealer Charged
Charging authority
Federal Bureau of Investigation
Main charges
Access device fraud-related offenses
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Maxim Rudometov

Alleged developer/administrator of RedLine Stealer. Current public status: Charged.

Charging authority
Federal Bureau of Investigation
Main charges
Access device fraud-related offenses
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Rows expand to show charging authority, case identifiers, custody status, and sources.

Group accounted for: Not established

The cited record does not say how large the group was or whether everyone involved has been identified.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Operation Magnus: RedLine and META infostealers dismantled

    Dutch National Police / operation-magnus.com, October 28, 2024, Source grade P1

    Establishes the Dutch-led takedown of RedLine and META Stealer infrastructure.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.