
What happened
Operation Endgame is a standing, multi-country effort against the loader and botnet services that deliver ransomware onto victim networks. Its own public record lists a first coordinated strike on 30 May 2024, which dismantled infrastructure behind IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee, made four arrests and took down more than 100 servers. A second strike followed in May 2025. On 22 May, the Department of Justice unsealed an indictment, which it says was taken 'in conjunction with Operation Endgame,' charging Rustam Rafailevich Gallyamov of Moscow as leader of the Qakbot conspiracy, alleging he ran spam-based attacks against American companies as recently as January 2025, two years after an earlier disruption of the same malware, and seeking forfeiture of more than twenty-four million dollars in seized cryptocurrency. The operation's site records that the wider action, publicised the next day, took down roughly 300 servers and 650 domains and produced twenty international arrest warrants. A further Europol-announced action, dated 13 November 2025, took down 1,025 servers tied to different infrastructure: the infostealer Rhadamanthys, the remote-access trojan VenomRAT and a botnet called Elysium.
Confidence and limits
The operation's own public accounting and a formal federal indictment corroborate each other on dates and scale. What is not established is whether the individuals named, including Gallyamov, are in custody; a sealed indictment charges someone with a crime, it does not convict them, and the record here should be read as an allegation with an outcome still pending, not a settled fact.
Why it mattered
Reading the three actions together says more than any single one. A network of loader services taken down in May 2024 did not end the underlying business model; new or adapted infrastructure was still large enough eighteen months later to justify a strike against over a thousand servers. That is not evidence the 2024 or 2025 actions failed; seizing infrastructure and arresting operators raises the cost and disrupts the service even when a market segment eventually regenerates. It is evidence that a single coordinated action is a recurring cost imposed on cybercriminal infrastructure, not a permanent removal of it, which is a more honest way to measure success than counting seized servers alone.
Defensive takeaway
Do not treat a well-publicised takedown of a loader or botnet family as reason to deprioritise detection for that family's techniques; monitor for the same delivery patterns even after an operator is reportedly disrupted, since successor infrastructure has repeatedly appeared within months in this operation's own record.
- Does your threat intelligence process retire indicators tied to a malware family once a takedown is announced, or track for its return?
- Would your defences still catch the delivery technique if the same loader reappeared under new infrastructure?
- Do you distinguish, in your own reporting, between an arrest and a conviction when describing an actor's status?
Three dated actions across eighteen months describe an unusually persistent law-enforcement campaign against a specific part of the cybercriminal supply chain, the loaders and botnets that hand off access to ransomware operators. The record supports calling it sustained pressure; it does not yet support calling it resolved.
Do not deprioritise detection for a malware family after a publicised takedown; monitor for the same delivery techniques, since successor infrastructure has repeatedly appeared within months in this operation's own record.
The operation's own public accounting and a formal federal indictment corroborate each other on dates and scale; whether named individuals, including Gallyamov, are in custody is not established, since an indictment charges rather than convicts.
Sources & reading trail
The joint operation's own record of the May 2024 first strike, the May 2025 second strike's server, domain and arrest-warrant figures, and the November 2025 follow-up action.
government-primary · Source published: Not established · Retrieved: 16 September 2026
DOJ's indictment of Rustam Rafailevich Gallyamov, taken in conjunction with Operation Endgame, and the related cryptocurrency forfeiture claim.
government-primary · Source published: 22 May 2025 · Retrieved: 16 September 2026
Europol's record of a further, larger Operation Endgame action in November 2025 against Rhadamanthys, VenomRAT and the Elysium botnet, taking down 1,025 servers.
government-primary · Source published: 13 November 2025 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.