Simda botnet disruption
Extended pass entry, last reviewed August 21, 2026
What was taken down?
C2 servers were seized or disrupted by participating national authorities in a coordinated action.
See what happenedWhat happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Not applicable
Did it stay down?
Not established in the public record. No later activity is recorded against this entry.
See what happened afterwardAn INTERPOL-coordinated operation with national police and private security firms targeted command-and-control servers of the Simda botnet, which affected systems in more than 190 countries.
- Date
- April 2015
- Target
- Simda, botnet
- Activity
- Malware and botnets
- Operational lead
- Not established
- Partners
- INTERPOL, Shadowserver[1]
- International Criminal Police Organization , coordinator
- The Shadowserver Foundation , technical partner
- Jurisdiction
- Not established
- Outcome
- C2 servers were seized or disrupted by participating national authorities in a coordinated action.
- Status
- Completed
- Legal mechanism
- Coordinated national judicial/search-and-seizure authority.
- Group accounted for
- Not applicable
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Not applicable
The cited record does not say how large the group was or whether everyone involved has been identified.
Reported to affect systems in more than 190 countries.
Not established in the public record. No later activity is recorded against this entry.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
Simda botnet disruption announcement
Establishes the INTERPOL-coordinated Simda C2 disruption.