Skip to main content
Back to the takedown index

Operation Source / Beebone botnet disruption

April 2015, Malware and botnets
Led by Politie (Netherlands National Police)

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Malicious domains were seized and sinkholed, allowing victim IP data to be supplied to ISPs and CERTs for remediation.

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not applicable

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

A Dutch-led action supported by Europol EC3/J-CAT, the FBI, and security-industry partners seized and sinkholed domains used by the polymorphic Beebone downloader botnet.

Date
April 2015
Target
Beebone, botnet
Activity
Malware and botnets
Operational lead
Dutch National Police
Partners
EC3, FBI[1]
Jurisdiction
Not established
Outcome
Malicious domains were seized and sinkholed, allowing victim IP data to be supplied to ISPs and CERTs for remediation.
Status
Completed
Legal mechanism
Dutch judicial/search-and-seizure authority; coordinated with US process for domains hosted there.
Group accounted for
Not applicable

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not applicable

The cited record does not say how large the group was or whether everyone involved has been identified.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Operation Source: Beebone botnet disruption

    Europol, April 8, 2015, Source grade P2

    Establishes the Dutch-led, Europol-supported Beebone domain seizure and sinkholing operation.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.