[Back to the takedown index](https://takedownindex.org/takedowns)

# Rustock botnet takedown

March 2011, [Malware and botnets](https://takedownindex.org/takedowns/categories/malware-and-botnets)
Led by [Microsoft Digital Crimes Unit](https://takedownindex.org/organizations/microsoft-digital-crimes-unit)

Source linked. Verified August 23, 2026.

What was taken down?

Command-and-control servers were seized from five hosting providers operating in seven US cities (Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus), and the IP addresses and domains used by the botnet were disabled, severing communication with the infected machines. Microsoft's Digital Crimes Unit estimated close to one million infected computers. The Dutch National High Tech Crime Unit helped dismantle the part of the command structure operating outside the United States.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

[See what happened](#what-happened)

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not established

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

Under an ex parte temporary restraining order and seizure order issued by the U.S. District Court for the Western District of Washington on 2011-03-09, the United States Marshals Service and Microsoft's Digital Crimes Unit executed the order on 2011-03-16, seizing Rustock command-and-control servers from five hosting providers across seven US cities and disabling the IP addresses and domains the botnet used.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

Announced March 17, 2011.

**Date:** March 2011

**Target:** Rustock, botnet

**Activity:** Malware and botnets

**Operational lead:** Microsoft DCU

**Partners**

USMS, NHTCU[[1]](#source-1)[[3]](#source-3)

- [United States Marshals Service](https://takedownindex.org/organizations/united-states-marshals-service), infrastructure seizure
- [National High Tech Crime Unit](https://takedownindex.org/organizations/national-high-tech-crime-unit), other

**Jurisdiction:** United States and Netherlands

**Outcome:** Command-and-control servers were seized from five hosting providers operating in seven US cities (Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus), and the IP addresses and domains used by the botnet were disabled, severing communication with the infected machines. Microsoft's Digital Crimes Unit estimated close to one million infected computers. The Dutch National High Tech Crime Unit helped dismantle the part of the command structure operating outside the United States.

**Status:** Completed

**Legal mechanism:** Ex parte temporary restraining order, seizure order and order to show cause issued 2011-03-09 by the U.S. District Court for the Western District of Washington in a civil action under the Computer Fraud and Abuse Act and the Lanham Act; executed by the United States Marshals Service

**Group accounted for:** Not established

### Infrastructure

Command and control servers seized, IP addresses disabled, domains disabled, and command and control servers disabled, with no count in the record.

| Identifier | Recorded as | Status | Notes |
| --- | --- | --- | --- |
| Not published | Command and control server | Seized, United States | Command-and-control servers seized from five hosting providers operating in seven US cities: Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus. No server count was published.[[3]](#source-3) |
| Not published | Ip address | Disabled, United States | IP addresses used for command and control were disabled pursuant to the seizure order. Appendix A of the TRO, which lists them, is not in the retrieved filings, so no count is recorded.[[1]](#source-1) |
| Not published | Domain | Disabled | Domains used by the botnet were disabled under the same order. No count or list was published in the retrieved filings.[[1]](#source-1) |
| Not published | Command and control server | Disabled | Part of the Rustock command structure operating outside the United States, dismantled with the Dutch National High Tech Crime Unit. The hosting country was not stated, so country\_code is null.[[3]](#source-3) |

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

## People and accountability

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not established

The defendants were anonymous John Does throughout; no operator was identified publicly by a government authority in this action.

Not established. The suit was pleaded against John Does 1-11, which is a pleading convention rather than a finding on the number of operators.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/rustock-botnet-takedown/organizations)

## What happened afterward

The civil case, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), was terminated on 2011-09-13. No government charging authority publicly named a Rustock operator in any source opened for this record.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

Not established in the public record. No later activity is recorded against this entry.

## Court cases

Court cases the audit located for this takedown. A case entry records a docket, not a summary of proceedings, and it establishes nothing about the guilt of anyone named in it.

- [Microsoft Corporation v. John Does 1-11 Controlling a Computer Botnet Thereby Injuring Microsoft and Its Customers](https://takedownindex.org/cases/microsoft-corporation-v-john-does-1-11-controlling-a-computer-botnet-thereby-inj). United States District Court for the Western District of Washington. Docket 2:11-cv-00222. Civil action filed 2011-02-09 before Judge James L. Robart; Second Amended Ex Parte Temporary Restraining O...

[Every court case in this index](https://takedownindex.org/cases).

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### What each part of this entry rests on

The audit recorded which sources carry which part of the record. These are those sources.

- Identity, dates and counts, [[1]](#source-1) [Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43](https://takedownindex.org/sources/united-states-district-court-for-the-western-district-of-washington-microsoft-co) , [[3]](#source-3) [Taking Down Botnets: Microsoft and the Rustock Botnet](https://takedownindex.org/sources/the-official-microsoft-blog-taking-down-botnets-microsoft-and-the-rustock-botnet)
- Agencies and roles, [[1]](#source-1) [Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43](https://takedownindex.org/sources/united-states-district-court-for-the-western-district-of-washington-microsoft-co) , [[3]](#source-3) [Taking Down Botnets: Microsoft and the Rustock Botnet](https://takedownindex.org/sources/the-official-microsoft-blog-taking-down-botnets-microsoft-and-the-rustock-botnet)
- Cases and status, [[2]](#source-2) [Microsoft Corporation v. Does, No. 2:11-cv-00222 (W.D. Wash.) docket record](https://takedownindex.org/sources/courtlistener-recap-microsoft-corporation-v-does-no-2-11-cv-00222-w-d-wash-docke) , [[1]](#source-1) [Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43](https://takedownindex.org/sources/united-states-district-court-for-the-western-district-of-washington-microsoft-co)

### Official sources

1.
[Microsoft Corporation's Status Report re Preliminary Injunction, Microsoft Corporation v. John Does 1-11, No. 2:11-cv-00222 (W.D. Wash.), Dkt. 43](https://takedownindex.org/sources/united-states-district-court-for-the-western-district-of-washington-microsoft-co)

United States District Court for the Western District of Washington, April 4, 2011, Source grade P0

Supporting detail not recorded.

[Open source](https://storage.courtlistener.com/recap/gov.uscourts.wawd.173532.43.0.pdf)
2.
[Microsoft Corporation v. Does, No. 2:11-cv-00222 (W.D. Wash.) docket record](https://takedownindex.org/sources/courtlistener-recap-microsoft-corporation-v-does-no-2-11-cv-00222-w-d-wash-docke)

CourtListener RECAP, Source grade P0

Supporting detail not recorded.

[Open source](https://www.courtlistener.com/api/rest/v4/search/?q=%22Rustock%22&type=r)

### Additional reporting and technical analysis

1.
[Taking Down Botnets: Microsoft and the Rustock Botnet](https://takedownindex.org/sources/the-official-microsoft-blog-taking-down-botnets-microsoft-and-the-rustock-botnet)

The Official Microsoft Blog, March 17, 2011, Source grade T1

Supporting detail not recorded.

[Open source](https://web.archive.org/web/20140710100518/http://blogs.technet.com/b/microsoft_blog/archive/2011/03/17/taking-down-botnets-microsoft-and-the-rustock-botnet.aspx)

Coverage note.
- Qualifies under the inclusion definition because the United States Marshals Service, executing a federal court seizure order, personally served the hosting companies listed in Appendix A of the TRO on 2011-03-16 and, with Microsoft, disabled the botnet's IP addresses and domains. The corpus previously carried Rustock in excluded\_meta as a 'purely private civil takedown', classified 'probable\_edge\_scope'; that classification is wrong on the facts of the court record.
- Microsoft also reported that CN-CERT blocked registration in China of domains Rustock could have used for future command and control. That is a preventive registry measure against domains not yet registered, so it is not recorded as an infrastructure item and CN is not in geographic\_scope.
- resurgence\_class left null: the A-G scale is undefined in this dataset and was not guessed.

Research context

## How this entry was checked

Source linked

Every claim in this entry traces to a source the audit opened and read. Nothing on the record needed changing.

Verified: August 23, 2026

Sources cited: 3

Research cutoff: August 23, 2026

Limitations recorded against this entry

- The count of seized servers, the identities of the five hosting providers and the number of disabled IP addresses and domains were not published; Appendix A of the TRO is not in the retrieved filings and the scanned docket PDFs carry no text layer.
- The seven-cities and five-providers figures come from Microsoft's own account, not from a government source.
- No US government press release for this action was located; the government role rests on the court filing and Microsoft's account.
- No source was opened on whether Rustock returned, so no resurgence row is proposed.

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Citadel botnet disruption](https://takedownindex.org/takedowns/citadel-botnet-disruption)
- [ZeroAccess botnet disruption](https://takedownindex.org/takedowns/zeroaccess-botnet-disruption)
- [Simda botnet disruption](https://takedownindex.org/takedowns/simda-botnet-disruption)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about/corrections-and-updates)
