RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Enforcement

Enforcement / From the archive · 22 May 2025 event · prepared 16 September 2026

A second Operation Endgame sweep seized hundreds of servers

Operation Endgame's own record and a DOJ indictment describe a second coordinated strike on loader services, and a third five months later.

Visual for this record: A second Operation Endgame sweep seized hundreds of servers
Visual published by justice.gov, shown for identification of the record. Credit: justice.gov · source page ↗ Rights: owner-review-pending.

What happened

Operation Endgame is a standing, multi-country effort against the loader and botnet services that deliver ransomware onto victim networks. Its own public record lists a first coordinated strike on 30 May 2024, which dismantled infrastructure behind IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee, made four arrests and took down more than 100 servers. A second strike followed in May 2025. On 22 May, the Department of Justice unsealed an indictment, which it says was taken 'in conjunction with Operation Endgame,' charging Rustam Rafailevich Gallyamov of Moscow as leader of the Qakbot conspiracy, alleging he ran spam-based attacks against American companies as recently as January 2025, two years after an earlier disruption of the same malware, and seeking forfeiture of more than twenty-four million dollars in seized cryptocurrency. The operation's site records that the wider action, publicised the next day, took down roughly 300 servers and 650 domains and produced twenty international arrest warrants. A further Europol-announced action, dated 13 November 2025, took down 1,025 servers tied to different infrastructure: the infostealer Rhadamanthys, the remote-access trojan VenomRAT and a botnet called Elysium.

Confidence and limits

The operation's own public accounting and a formal federal indictment corroborate each other on dates and scale. What is not established is whether the individuals named, including Gallyamov, are in custody; a sealed indictment charges someone with a crime, it does not convict them, and the record here should be read as an allegation with an outcome still pending, not a settled fact.

Why it mattered

Reading the three actions together says more than any single one. A network of loader services taken down in May 2024 did not end the underlying business model; new or adapted infrastructure was still large enough eighteen months later to justify a strike against over a thousand servers. That is not evidence the 2024 or 2025 actions failed; seizing infrastructure and arresting operators raises the cost and disrupts the service even when a market segment eventually regenerates. It is evidence that a single coordinated action is a recurring cost imposed on cybercriminal infrastructure, not a permanent removal of it, which is a more honest way to measure success than counting seized servers alone.

Defensive takeaway

Do not treat a well-publicised takedown of a loader or botnet family as reason to deprioritise detection for that family's techniques; monitor for the same delivery patterns even after an operator is reportedly disrupted, since successor infrastructure has repeatedly appeared within months in this operation's own record.

  • Does your threat intelligence process retire indicators tied to a malware family once a takedown is announced, or track for its return?
  • Would your defences still catch the delivery technique if the same loader reappeared under new infrastructure?
  • Do you distinguish, in your own reporting, between an arrest and a conviction when describing an actor's status?

Three dated actions across eighteen months describe an unusually persistent law-enforcement campaign against a specific part of the cybercriminal supply chain, the loaders and botnets that hand off access to ransomware operators. The record supports calling it sustained pressure; it does not yet support calling it resolved.

Defensive takeaway

Do not deprioritise detection for a malware family after a publicised takedown; monitor for the same delivery techniques, since successor infrastructure has repeatedly appeared within months in this operation's own record.

The operation's own public accounting and a formal federal indictment corroborate each other on dates and scale; whether named individuals, including Gallyamov, are in custody is not established, since an indictment charges rather than convicts.

Sources & reading trail

Operation Endgame – News ↗

The joint operation's own record of the May 2024 first strike, the May 2025 second strike's server, domain and arrest-warrant figures, and the November 2025 follow-up action.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Leader of Qakbot Malware Conspiracy Indicted for Involvement in Global Ransomware Scheme ↗

DOJ's indictment of Rustam Rafailevich Gallyamov, taken in conjunction with Operation Endgame, and the related cryptocurrency forfeiture claim.

government-primary · Source published: 22 May 2025 · Retrieved: 16 September 2026

End of the game for cybercrime infrastructure: 1025 servers taken down ↗

Europol's record of a further, larger Operation Endgame action in November 2025 against Rhadamanthys, VenomRAT and the Elysium botnet, taking down 1,025 servers.

government-primary · Source published: 13 November 2025 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.