Rustock botnet takedown
Source linked. Verified August 23, 2026.
What was taken down?
Command-and-control servers were seized from five hosting providers operating in seven US cities (Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus), and the IP addresses and domains used by the botnet were disabled, severing communication with the infected machines. Microsoft's Digital Crimes Unit estimated close to one million infected computers. The Dutch National High Tech Crime Unit helped dismantle the part of the command structure operating outside the United States.[1][2][3]
See what happenedWhat happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Not established
Did it stay down?
Not established in the public record. No later activity is recorded against this entry.
See what happened afterwardUnder an ex parte temporary restraining order and seizure order issued by the U.S. District Court for the Western District of Washington on 2011-03-09, the United States Marshals Service and Microsoft's Digital Crimes Unit executed the order on 2011-03-16, seizing Rustock command-and-control servers from five hosting providers across seven US cities and disabling the IP addresses and domains the botnet used.[1][2][3]
Announced March 17, 2011.
- Date
- March 2011
- Target
- Rustock, botnet
- Activity
- Malware and botnets
- Operational lead
- Microsoft DCU
- Partners
- USMS, NHTCU[1][3]
- United States Marshals Service , infrastructure seizure
- National High Tech Crime Unit , other
- Jurisdiction
- United States and Netherlands
- Outcome
- Command-and-control servers were seized from five hosting providers operating in seven US cities (Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus), and the IP addresses and domains used by the botnet were disabled, severing communication with the infected machines. Microsoft's Digital Crimes Unit estimated close to one million infected computers. The Dutch National High Tech Crime Unit helped dismantle the part of the command structure operating outside the United States.
- Status
- Completed
- Legal mechanism
- Ex parte temporary restraining order, seizure order and order to show cause issued 2011-03-09 by the U.S. District Court for the Western District of Washington in a civil action under the Computer Fraud and Abuse Act and the Lanham Act; executed by the United States Marshals Service
- Group accounted for
- Not established
Infrastructure
Command and control servers seized, IP addresses disabled, domains disabled, and command and control servers disabled, with no count in the record.
| Identifier | Recorded as | Status | Notes |
|---|---|---|---|
| Not published | Command and control server | Seized, United States | Command-and-control servers seized from five hosting providers operating in seven US cities: Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus. No server count was published.[3] |
| Not published | Ip address | Disabled, United States | IP addresses used for command and control were disabled pursuant to the seizure order. Appendix A of the TRO, which lists them, is not in the retrieved filings, so no count is recorded.[1] |
| Not published | Domain | Disabled | Domains used by the botnet were disabled under the same order. No count or list was published in the retrieved filings.[1] |
| Not published | Command and control server | Disabled | Part of the Rustock command structure operating outside the United States, dismantled with the Dutch National High Tech Crime Unit. The hosting country was not stated, so country_code is null.[3] |
Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Not established
The defendants were anonymous John Does throughout; no operator was identified publicly by a government authority in this action.
Not established. The suit was pleaded against John Does 1-11, which is a pleading convention rather than a finding on the number of operators.
The civil case, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), was terminated on 2011-09-13. No government charging authority publicly named a Rustock operator in any source opened for this record.[1][2][3]
Not established in the public record. No later activity is recorded against this entry.
Court cases the audit located for this takedown. A case entry records a docket, not a summary of proceedings, and it establishes nothing about the guilt of anyone named in it.
- Microsoft Corporation v. John Does 1-11 Controlling a Computer Botnet Thereby Injuring Microsoft and Its Customers . United States District Court for the Western District of Washington . Docket 2:11-cv-00222 . Civil action filed 2011-02-09 before Judge James L. Robart; Second Amended Ex Parte Temporary Restraining O...
Numbered markers throughout this entry link to the source that supports the claim beside them.
What each part of this entry rests on
The audit recorded which sources carry which part of the record. These are those sources.
- Identity, dates and counts, [1] Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43 , [3] Taking Down Botnets: Microsoft and the Rustock Botnet
- Agencies and roles, [1] Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43 , [3] Taking Down Botnets: Microsoft and the Rustock Botnet
- Cases and status, [2] Microsoft Corporation v. Does, No. 2:11-cv-00222 (W.D. Wash.) docket record , [1] Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43
Official sources
-
[1]
Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43Open source
Supporting detail not recorded.
-
[2]
Microsoft Corporation v. Does, No. 2:11-cv-00222 (W.D. Wash.) docket recordOpen source
Supporting detail not recorded.
Additional reporting and technical analysis
-
[3]
Taking Down Botnets: Microsoft and the Rustock BotnetOpen source
Supporting detail not recorded.
- Qualifies under the inclusion definition because the United States Marshals Service, executing a federal court seizure order, personally served the hosting companies listed in Appendix A of the TRO on 2011-03-16 and, with Microsoft, disabled the botnet's IP addresses and domains. The corpus previously carried Rustock in excluded_meta as a 'purely private civil takedown', classified 'probable_edge_scope'; that classification is wrong on the facts of the court record.
- Microsoft also reported that CN-CERT blocked registration in China of domains Rustock could have used for future command and control. That is a preventive registry measure against domains not yet registered, so it is not recorded as an infrastructure item and CN is not in geographic_scope.
- resurgence_class left null: the A-G scale is undefined in this dataset and was not guessed.