Skip to main content
Back to Rustock botnet takedown

Organizations and roles

March 2011, Malware and botnets
Rustock botnet takedown

Last reviewed August 23, 2026

The public record puts 3 organizations on this action. Operational lead: Microsoft DCU. The table lists the role the cited record assigns each one, in the record's own wording where it gives any.

Why this page names organizations only

Roles on this page describe the agencies that took part. Individuals named in the public record appear on the takedown entry itself, under People and accountability.

Organizations and roles

Emblem Organization Role What the record says
Microsoft Digital Crimes Unit United States , United States Operational lead Microsoft Digital Crimes Unit brought the civil action (Operation b107), obtained the ex parte seizure order and directed the technical takedown.
United States Marshals Service United States , United States Infrastructure seizure Executed the court's seizure order on 2011-03-16, personally serving the hosting companies listed in Appendix A of the TRO and escorting the seizure of command-and-control servers.
National High Tech Crime Unit Netherlands , Netherlands Other Helped dismantle the part of the Rustock command structure operating outside the United States.

Accountability

Legal authority

Ex parte temporary restraining order, seizure order and order to show cause issued 2011-03-09 by the U.S. District Court for the Western District of Washington in a civil action under the Computer Fraud and Abuse Act and the Lanham Act; executed by the United States Marshals Service

This page records organizational involvement as the cited sources state it. Where a role carries no description, the record gives none.

Last reviewed August 23, 2026