Law enforcement dismantled infrastructure of seven malware strains: Bumblebee, Lactrodectus, Qakbot, Hijackloader, DanaBot, Trickbot, and Warmcookie.

On May 23, 2025, Europol and Eurojust announced the coordination of “Endgame 2.0,” an international operation targeting initial access malware used by ransomware gangs. Authorities from seven countries participated: Germany, Canada, Denmark, the United States, France, the Netherlands, and the United Kingdom. France was represented by the national police and gendarmerie, the Paris Judicial Police Directorate, and the National Jurisdiction for Combating Organized Crime (Junalco).

Between May 19 and 22, investigators jointly dismantled the infrastructure of seven malware strains: Bumblebee, Lactrodectus, Qakbot, Hijackloader, DanaBot, Trickbot, and Warmcookie. “By disabling these entry points, investigators struck at the very beginning of the cyberattack chain, thereby disrupting the entire cybercrime ecosystem,” stated Europol’s release.

Law enforcement seized over 300 servers worldwide, including around fifty in Germany, 650 domain names, and €3.5 million in cryptocurrency. Judicial authorities also issued about twenty international arrest warrants, most targeting Russian nationals.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.