Western allies move on malware network as operation seizes crypto and knocks out servers
*Event date: 2025-05-23*
Authorities in Canada, Denmark, France, Germany, the Netherlands, Britain and the United States have carried out a coordinated crackdown on malware infrastructure that Europol and Eurojust described as among the world’s most dangerous.
The operation disrupted more than 300 servers, neutralized 650 domains and seized about €3.5 million, or $3.9 million, in cryptocurrency, according to the agencies. Eurojust said the effort unfolded between Monday and Thursday and led to international arrest warrants for 20 people. Thirty-seven suspects were identified in total.
The action targeted what investigators call “initial access malware,” software used to get into victims’ systems before criminals add other tools, including ransomware. Europol and Eurojust said that disrupting those entry points damages the wider cybercrime ecosystem because the malware sits at the start of the attack chain.
The targeted names read like a cross-section of a long-running criminal market: Bumblebee, Lactrodectus, Qakbot, DanaBot, HijackLoader, Trickbot and WarmCookie were among the variants named by the authorities. The agencies did not say in the excerpt how long each strain had been active, but they framed the intervention as an extension of Operation Endgame, the largest police action ever conducted against botnets.
Germany was a major focus. About 50 of the neutralized servers were in Germany, and German authorities said their investigations centered on suspected organised extortion and membership in a foreign criminal organization. The federal police and Frankfurt public prosecutor’s office also said international arrest warrants were issued for the 20 people, most of them Russian nationals, and search operations were launched.
The seizure figure was also presented in the context of the wider Operation Endgame campaign, which began in 2024. Europol and Eurojust said that by interrupting the malware supply chain early, investigators were aiming not just at individual machines but at the broader infrastructure that allows cybercrime services to keep running.
The public takeaway from the operation is less about a single takedown than the scale of the joint response. Instead of one national case, investigators from seven countries moved together against a distributed network of servers, domains and suspects tied to malware used for early-stage compromise. The agencies said the effort was intended to hit the point where attackers first gain access, before they can pivot into ransomware, extortion or other forms of follow-on abuse.
The action leaves open how quickly the disrupted services can be rebuilt. But the numbers released by Europol and Eurojust suggest the week’s operation was designed to do more than inconvenience operators. By taking down servers, freezing or seizing crypto and obtaining arrest warrants across borders, the participating authorities attempted to cut off the technical and financial plumbing that underpins malware distribution at scale.
For now, the best public measure of success is the breadth of the operation itself: seven countries, hundreds of servers, hundreds of domains, and a long list of malware families that investigators say were pushed offline or degraded in a single multinational push.



