Ramnit botnet disruption
Extended pass entry, last reviewed August 21, 2026
What was taken down?
Servers and domains supporting the botnet were taken under law-enforcement control and routed to a sinkhole.
See what happenedWhat happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Not applicable
Did it stay down?
Not established in the public record. No later activity is recorded against this entry.
See what happened afterwardA Europol-supported coalition of European national police and security-industry partners disrupted Ramnit botnet infrastructure, which Europol estimated had infected roughly 3.2 million computers.
- Date
- February 2015
- Target
- Ramnit, botnet
- Activity
- Malware and botnets
- Operational lead
- Not established
- Partners
- Europol[1]
- European Union Agency for Law Enforcement Cooperation , coordinator
- Jurisdiction
- Not established
- Outcome
- Servers and domains supporting the botnet were taken under law-enforcement control and routed to a sinkhole.
- Status
- Completed
- Legal mechanism
- Coordinated national judicial/search-and-seizure authority; exact statute per country not publicly detailed.
- Group accounted for
- Not applicable
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Not applicable
The cited record does not say how large the group was or whether everyone involved has been identified.
Europol estimated approximately 3.2 million infected computers.
Not established in the public record. No later activity is recorded against this entry.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
Ramnit botnet disruption announcement
Establishes the Europol-coordinated Ramnit infrastructure disruption and the 3.2 million infection estimate.