Skip to main content
Back to the takedown index

Rustock botnet takedown

March 2011, Malware and botnets
Led by Microsoft Digital Crimes Unit

Source linked. Verified August 23, 2026.

What was taken down?

Command-and-control servers were seized from five hosting providers operating in seven US cities (Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus), and the IP addresses and domains used by the botnet were disabled, severing communication with the infected machines. Microsoft's Digital Crimes Unit estimated close to one million infected computers. The Dutch National High Tech Crime Unit helped dismantle the part of the command structure operating outside the United States.[1][2][3]

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not established

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

Under an ex parte temporary restraining order and seizure order issued by the U.S. District Court for the Western District of Washington on 2011-03-09, the United States Marshals Service and Microsoft's Digital Crimes Unit executed the order on 2011-03-16, seizing Rustock command-and-control servers from five hosting providers across seven US cities and disabling the IP addresses and domains the botnet used.[1][2][3]

Announced March 17, 2011.

Date
March 2011
Target
Rustock, botnet
Activity
Malware and botnets
Operational lead
Microsoft DCU
Partners
USMS, NHTCU[1][3]
Jurisdiction
United States and Netherlands
Outcome
Command-and-control servers were seized from five hosting providers operating in seven US cities (Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus), and the IP addresses and domains used by the botnet were disabled, severing communication with the infected machines. Microsoft's Digital Crimes Unit estimated close to one million infected computers. The Dutch National High Tech Crime Unit helped dismantle the part of the command structure operating outside the United States.
Status
Completed
Legal mechanism
Ex parte temporary restraining order, seizure order and order to show cause issued 2011-03-09 by the U.S. District Court for the Western District of Washington in a civil action under the Computer Fraud and Abuse Act and the Lanham Act; executed by the United States Marshals Service
Group accounted for
Not established

Infrastructure

Command and control servers seized, IP addresses disabled, domains disabled, and command and control servers disabled, with no count in the record.

Identifier Recorded as Status Notes
Not published Command and control server Seized, United States Command-and-control servers seized from five hosting providers operating in seven US cities: Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus. No server count was published.[3]
Not published Ip address Disabled, United States IP addresses used for command and control were disabled pursuant to the seizure order. Appendix A of the TRO, which lists them, is not in the retrieved filings, so no count is recorded.[1]
Not published Domain Disabled Domains used by the botnet were disabled under the same order. No count or list was published in the retrieved filings.[1]
Not published Command and control server Disabled Part of the Rustock command structure operating outside the United States, dismantled with the Dutch National High Tech Crime Unit. The hosting country was not stated, so country_code is null.[3]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not established

The defendants were anonymous John Does throughout; no operator was identified publicly by a government authority in this action.

Not established. The suit was pleaded against John Does 1-11, which is a pleading convention rather than a finding on the number of operators.

See the organizations and roles behind this action

The civil case, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), was terminated on 2011-09-13. No government charging authority publicly named a Rustock operator in any source opened for this record.[1][2][3]

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

What each part of this entry rests on

The audit recorded which sources carry which part of the record. These are those sources.

Official sources

  1. [1]
    Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43

    United States District Court for the Western District of Washington, April 4, 2011, Source grade P0

    Supporting detail not recorded.

    Open source
  2. [2]
    Microsoft Corporation v. Does, No. 2:11-cv-00222 (W.D. Wash.) docket record

    CourtListener RECAP, Source grade P0

    Supporting detail not recorded.

    Open source

Additional reporting and technical analysis

  1. [3]
    Taking Down Botnets: Microsoft and the Rustock Botnet

    The Official Microsoft Blog, March 17, 2011, Source grade T1

    Supporting detail not recorded.

    Open source
Coverage note.
  • Qualifies under the inclusion definition because the United States Marshals Service, executing a federal court seizure order, personally served the hosting companies listed in Appendix A of the TRO on 2011-03-16 and, with Microsoft, disabled the botnet's IP addresses and domains. The corpus previously carried Rustock in excluded_meta as a 'purely private civil takedown', classified 'probable_edge_scope'; that classification is wrong on the facts of the court record.
  • Microsoft also reported that CN-CERT blocked registration in China of domains Rustock could have used for future command and control. That is a preventive registry measure against domains not yet registered, so it is not recorded as an infrastructure item and CN is not in geographic_scope.
  • resurgence_class left null: the A-G scale is undefined in this dataset and was not guessed.