[Back to the takedown index](https://takedownindex.org/takedowns)

# Operation Magnus (RedLine and META infostealers)

October 2024, Malware and botnets
Led by [Politie (Netherlands National Police)](https://takedownindex.org/organizations/politie-netherlands-national-police)

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Servers seized; source code and backend databases obtained.

[See what happened](#what-happened)

What happened to the people?

1 charged named in the public record.
Group accounted for: Not established

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

Dutch-led Operation Magnus, coordinated with Eurojust, Europol, FBI, and other partners, took down the infrastructure of the RedLine and META infostealer malware families.

**Date:** October 2024

**Target:** RedLine Stealer and META Stealer, infostealer malware

**Activity:** Malware and botnets

**Operational lead:** Dutch National Police

**Partners**

Eurojust, FBI[[1]](#source-1)

- [European Union Agency for Criminal Justice Cooperation](https://takedownindex.org/organizations/european-union-agency-for-criminal-justice-cooperation), coordinator
- [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation), supporting

**Jurisdiction:** Not established

**Outcome:** Servers seized; source code and backend databases obtained.

**Status:** Completed

**Legal mechanism:** Dutch judicial search/seizure authority; coordinated international warrants.

**Group accounted for:** Not established

## People and accountability

Named in the public record: 1 charged.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

#### Maxim Rudometov

Alleged developer/administrator of RedLine Stealer. Current public status: Charged.

**Charging authority:** Federal Bureau of Investigation

**Main charges:** Access device fraud-related offenses

**Case number:** Not established in the public record

**Arresting authority:** Not established in the public record

**Arrest location:** Not established in the public record

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[1]](#source-1)

**Full record:** [Everything indexed for Maxim Rudometov](https://takedownindex.org/people/maxim-rudometov)

Group accounted for: Not established

The cited record does not say how large the group was or whether everyone involved has been identified.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/operation-magnus-redline-and-meta-infostealers/organizations)

## What happened afterward

Not established in the public record. No later activity is recorded against this entry.

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[Operation Magnus: RedLine and META infostealers dismantled](https://takedownindex.org/sources/dutch-national-police-operation-magnus-com-operation-magnus-redline-and-meta-inf)

Dutch National Police / operation-magnus.com, October 28, 2024, Source grade P1

Establishes the Dutch-led takedown of RedLine and META Stealer infrastructure.

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source\_quality capped at S2/P2 pending a dedicated verification pass.

Research context

## How this entry was checked

This entry came from a broader aggregation pass and has not been independently verified source by source. Its sources are graded no higher than P2 or S2, and most carry no address yet. Treat the figures as a research lead rather than a settled record.

Source review: Extended pass, not yet verified

Sources cited: 1

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Matrix encrypted messaging service takedown](https://takedownindex.org/takedowns/matrix-encrypted-messaging-service-takedown)
- [Operation Endgame wave 1](https://takedownindex.org/takedowns/operation-endgame-wave-1)
- [Operation Deep Sentinel](https://takedownindex.org/takedowns/operation-deep-sentinel)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
