Cybercrime DB

Botnet Infrastructure Dismantlement Operations

How law enforcement and security vendors coordinate to permanently dismantle botnet infrastructure.

Editor at Large · · 12 min read
Cover illustration for “Botnet Infrastructure Dismantlement Operations”
cybercrime takedowns and seizures · September 15, 2026 · 12 min read · 2,682 words

A botnet doesn't die when you unplug one server. It dies (if it dies at all) when law enforcement, security vendors, and infrastructure providers hit domains, servers, and command channels at the same time, fast enough that operators can't just move next door. That is what the whole game consists of. This piece walks through how that machinery actually works, using real 2024 through 2026 cases as the evidence, and why some botnets stay dead while others show up again six months later wearing a new version number.

Start with the shape of the thing you're trying to kill. A botnet isn't one machine, it's a stack: infected endpoints at the bottom, command-and-control (C2) servers in the middle, domains and IP addresses routing traffic between them, and a monetization layer on top that turns infected machines into money (ransomware delivery, credential theft, proxy rental, straight-up fraud). Increasingly, that stack is a rental business. Botnet operators lease installs to ransomware crews, initial access brokers, and fraud operators, which means taking down one node doesn't collapse the ecosystem around it. It just means the tenants find a new landlord.

The architecture is built to survive exactly this kind of attack. Peer-to-peer (P2P) command routing means there's no single C2 server to seize, because infected machines pass instructions to each other directly. Domain generation algorithms (DGAs) spit out new C2 addresses faster than a court can issue a seizure order. Fast flux networks rotate IP addresses continuously. Polymorphic code changes its own signature to dodge detection tools. And the attack surface keeps growing: per Barracuda's 2026 botnet landscape report, roughly 60% of all IoT devices in 2025 were consumer-grade, and about 35% of global DDoS traffic now originates from IoT botnets. Every mechanism described below exists to defeat one or more of those resilience features. Keep that in mind as the sections unfold, because it's the whole plot.

Before anyone seizes a server, someone has to have the legal right to do it. Four instruments make that possible: civil injunctions, seizure warrants, criminal charges, and sanctions.

Civil injunctions sound like the easy button, but they're not available for just any botnet. Courts limit them to cases involving wiretapping violations or specific fraud elements, which forces prosecutors to build a case around a statutory hook rather than just arguing "this infrastructure is bad and should go away." Seizure warrants cover domains and physical servers. Criminal charges open the door to arrests and extradition. And when the actor is state-linked rather than a lone operator looking to make rent, sanctions become the tool of choice: the response to the Flax Typhoon threat group is a clean example of prosecution simply not being on the table.

None of this works across borders without a coordination layer. Mutual legal assistance treaties (MLATs) and standing partnerships like Europol task forces are what let a warrant issued in one country actually mean something in another. Without them, an operator just moves the server across a border and waits. Private companies matter here too, hosting providers, domain registrars, CDNs, security vendors. They show up by name in DOJ announcements because their cooperation isn't a courtesy, it's structurally required to make a seizure order into an actual seizure.

Worth separating two things that get lumped together: disruptive operations (seizing servers, taking over domains) and prosecutorial operations (charges, arrests). They often run side by side, but they move on different clocks and get judged by different measures of success. A server seizure can happen in a weekend. A prosecution can take years.

Domain seizures and DNS sinkholing as the first strike in most operations

Most takedowns open the same way: DNS sinkholing. Law enforcement, or a partner security operator, takes control of the C2 domains and redirects all that bot traffic to a server they control instead. That does two things at once. It cuts the operator off from their own fleet, and it hands investigators a live feed of every infected machine still trying to phone home.

The scale of these domain seizures can get enormous. In the March 2026 IoT botnet cluster operation, the DOD Inspector General's Defense Criminal Investigative Service executed seizure warrants across U.S.-registered domains and virtual servers tied to four separate botnets, Aisuru, KimWolf, JackSkid, and Mossad. Operation Endgame's first phase, run over May 27 to 29, 2024, put more than 2,000 domains and over 100 servers under law enforcement control in a single weekend. That domain count tells you something on its own: these operators leaned hard on registered domains to keep rotating their C2 infrastructure, and law enforcement matched that volume directly.

One thing sinkholing does not do: clean infected machines. It severs the operator's remote control, but the malware stays put until someone removes it. That distinction drives everything about victim notification that follows a takedown, because "your traffic hit our sinkhole" is not the same as "your machine is fixed."

DGA-equipped botnets complicate this further. If an operator can algorithmically generate tomorrow's C2 domain today, sinkholing yesterday's domain accomplishes very little. Investigators either have to predict and register future domains ahead of time, or fall back on a different mechanism entirely, which is where things get genuinely hard.

P2P sinkholing: the more complex operation the Sality takedown demonstrates

Sality is the case that shows what happens when there's no domain to seize at all. On August 31, 2026, CrowdStrike's Counter Adversary Operations team, alongside international law enforcement and the Shadowserver Foundation, disrupted a P2P botnet that had been running for more than two decades and had pushed payloads to tens of thousands of infected machines worldwide. DOJ actions followed across the U.S., Bulgaria, Hungary, and Romania. CrowdStrike tracks the group behind it as SALTY SPIDER, assessed as likely operating out of Bashkortostan, Russia.

Here's the mechanical difference from a domain takedown. Sality machines don't call a C2 server, they talk to each other. So instead of seizing an address, investigators inject purpose-built sinkhole nodes into the peer lists of already-compromised machines. Once a high-connectivity "super peer" has its list purged, it stops passing along malicious payloads to the rest of the network. Target the super peers first, because the whole mesh depends on them the way a subway system depends on its transfer stations. Take out the hubs and the local lines stop connecting to anything.

The wrinkle is that most Sality infections sit behind firewalls or NAT, meaning they can't be reached directly at all. For those machines, the approach is patient rather than aggressive: when an infected host checks in during its normal maintenance cycle, its peer list gets purged on contact, leaving it permanently isolated the next time it tries to reach the network. And even after the disruption itself is done, the sinkhole nodes keep working, feeding ongoing visibility into infection numbers and supporting victim notification long after the initial operation wraps.

A related case makes the same point about disclosure as a tool in itself. On May 26, 2026, CrowdStrike's Counter Adversary Operations executed a takedown of Glassworm, a botnet targeting software developers globally. Every infected Glassworm machine now beacons to a benign, CrowdStrike-operated sinkhole address, 164.92.88[.]210. Publishing that IP gives security teams a concrete indicator to search for in their logs.

Server seizures and how physical infrastructure actions fit into multi-phase operations

Seizing a server by itself rarely ends anything. Rent a new box, point the malware at it, done, sometimes within hours, assuming the domain infrastructure and P2P layer are still intact. Server seizures earn their keep only when they land at the same moment as sinkholing, so the operator loses the building and the phone line on the same afternoon.

Operation Endgame shows how this compounds across phases, with each round of seizures feeding intelligence into the next. Phase 1 in May 2024 took more than 100 servers. Phase 2, branded Endgame 2.0, ran in May 2025 and hit more than 300 servers, brought criminal charges against 20 individuals, and seized €3.5 million in cryptocurrency. Phase 3, Endgame 3.0, landed in November 2025 with 1,025 servers across more than 20 countries, targeting Rhadamanthys, VenomRAT, and the Elysium botnet. None of that third phase happens without the mapping data recovered in the first two.

The 911 S5 takedown in May 2024 shows a similar scale problem from a different angle: 23 domains and more than 70 servers disrupted in a joint action across a large home country, Singapore, Thailand, and Germany, with roughly $30 million in assets seized. That botnet was tied to more than 19 million unique IP addresses, 613,841 of them inside the United States alone.

Synchronizing that across 20-plus countries is not a routine Tuesday for anyone involved. Warrants, timing, physical access, none of it lines up on its own, and some seizures happen with hosting providers cooperating voluntarily while others require investigators to physically image or remove hardware because nobody asked nicely first.

Arrests, public identification, and the psychological operations layer

Arrests are the rarest outcome in this entire chain, and the gap is stark. Operation Endgame's first phase disrupted infrastructure across many countries but produced exactly four arrests, one in Armenia, three in Ukraine. Servers are property. People have lawyers, passports, and governments that may or may not answer an extradition request.

So when arrest isn't realistic, public identification becomes the substitute weapon. After Endgame Phase 1, Europol added eight fugitives to Europe's Most Wanted list, naming Russian nationals by handle and role: Airat Rustemovich Gruber as the SmokeLoader administrator, and TrickBot members Oleg Kucherov, Sergey Polyak, Fedor Andreev, Georgy Tesman, Anton Bragin, Andrei Cherepanov, and Nikolai Chereshnev. Nobody expects most of these names to see a courtroom soon. Hiding should feel uncomfortable.

The SmokeLoader follow-on in early 2025 shows a sharper version of the same idea. Investigators seized SmokeLoader's customer database, and that database turned out to be worth more than the server it sat on, because it let them match online handles to real identities. What followed ranged from knock-and-talks to house searches to actual arrests. The data was the prize, not the hardware.

Operation Endgame also leaned into something closer to theater, and it worked as strategy rather than as a punchline: a dedicated website, illustrated videos of visibly nervous operators, and direct messages to suspects reading "Think About (Y)Our Next Move." This approach functioned as a pressure tactic, meant to unsettle people who know they're being watched but can't be arrested yet.

The March 2026 IoT cluster case follows the same script. Law enforcement in Canada and Germany targeted named individuals, and KrebsOnSecurity identified a 22-year-old Canadian and a 15-year-old in Germany as the operators behind KimWolf, with public identification arriving before any formal charges. And in the 911 S5 case, YunHe Wang, 35, a Chinese national who'd obtained citizenship through St. Kitts and Nevis's investment program, was actually arrested and charged with building and running the botnet, one of the few times the person actually running things ended up reachable.

Why some takedowns hold and others produce only a temporary pause

Start with the counter-evidence, because it's more instructive than the wins. DanaBot went quiet after Operation Endgame's May 2025 phase, then came back in a rebuilt form. TrickBot was disrupted and later reemerged in a new form with fresh ransomware ties. Emotet was taken down and later resurfaced in a rebuilt form. None of these are failures of the takedown mechanics described above, they're evidence of what those mechanics can and can't accomplish.

As one analyst framing of past operations makes clear, takedowns of malware like TrickBot and Emotet reduced use of it but didn't eliminate it. Reduction, not elimination. That's the realistic bar, and treating it as anything higher just sets up the next relapse as a surprise when it isn't one.

Three things seem to predict whether a takedown sticks. Whether operators got arrested or just displaced, since displaced operators rebuild and arrested ones don't. Whether the sinkholing reached machines hiding behind NAT and firewalls, or only caught the ones sitting out in the open. And whether the operation cut off the money, seized cryptocurrency, broken customer databases, rather than just knocking over the delivery pipeline.

Endgame's phased model holds up better than one-shot seizures for exactly this reason: each round degrades the operators' ability to reconstitute, and 1,025 servers across more than 20 countries in Phase 3 followed the intelligence gathered across Phases 1 and 2.

Mirai is the case that shows the limit of all of this. Its source code has been public for years, and researchers tracked more than 116 distinct Mirai variant branches in 2025, with Barracuda's 2026 report clocking a 50% jump in Mirai-related C2 infrastructure. Arrests can't stop code from being re-forked when anyone with a laptop can copy and paste it into a new botnet by dinner. Add to that a genuine research gap: not many studies systematically track how these operations actually change attacker behavior over time, which means the evidence behind "this takedown worked" is thinner than the press release makes it sound, and it's worth holding vendor claims to that same standard.

State-sponsored botnets sit outside this whole framework. Flax Typhoon compromised more than 260,000 devices, roughly half of them in a single large country, and a federal law enforcement agency used court-authorized commands to strip malware off infected machines directly. But the sponsoring state doesn't face prosecution, it faces sanctions, OFAC's action against Integrity Technology Group being the example here. The infrastructure can be dismantled completely and the capability behind it just keeps existing, waiting for the next campaign.

What practitioners and security vendors should actually take from takedown operations

Sinkhole disclosures aren't just documentation, they're live threat intel. When CrowdStrike published 164.92.88[.]210 as the Glassworm sinkhole address and told organizations to check their logs against it, that single IP became a detection rule that any security team could act on immediately. That model shows how a vendor's role in a takedown turns into something a practitioner can use Monday morning.

Treat every takedown announcement as a window, not a verdict. The weeks right after a major operation are exactly when operators are rewriting code and reseeding infrastructure, which makes that stretch the most useful time to be watching for re-emergence, not the moment to file the case closed.

The material that outlasts any individual takedown is the indicator and behavior data pulled out of it, things like Intel 471's hunter detections published alongside their Endgame analysis. Network indicators, peer-list purge signatures, behavioral patterns, all of that keeps working long after the specific botnet it came from has been rebuilt under a new name.

Scale matters for calibrating how loud to be about any of this. Cloudflare's Q4 2024 DDoS Threat Report showed total attacks up 53% year over year, with a peak of 1.14 Tbps, 65% above 2023's record of 0.69 Tbps. Against numbers like that, vague "botnets are dangerous" messaging just reads as filler. What actually earns attention is content tied to specific, live operations, the kind of detail this piece has been walking through.

The coordination model itself is the tell. CrowdStrike and Shadowserver working alongside DOJ on Sality, or the roughly 20-partner lineup including Akamai, AWS, Google, and Cloudflare on the IoT cluster case, shows that the most credible security companies earn that credibility by showing up inside the operation, not by commenting on it after the fact. Threat intelligence feeds that track these disruptions as they happen, rather than summarizing them weeks later, are what let a security team tell which mechanism actually beat which architecture, sinkholing versus P2P routing, seizure versus a domain-generation-based evasion technique. Cyberou is one vendor operating in that space, tracking disruption outcomes as they unfold rather than reconstructing them from press releases. Whether it's one particular feed or another, the standard is the same. Content anchored in the actual mechanics holds up in a way that generic warnings about "growing botnet threats" simply doesn't, and that includes super-peer targeting, the database-to-identity chain in SmokeLoader, and an address-rotation-and-cleanup cycle in Sality.

Sources

  1. What the Biggest-Ever Botnet Takedown Means | Intel 471
  2. Top threat trends of the 2025 botnet landscape
  3. Top threats of the 2024 botnet landscape
  4. US, allies move to dismantle four high-volume IoT botnets
  5. cybersecuritydive.com
  6. crowdstrike.com
  7. thehackernews.com
  8. europol.europa.eu

More in cybercrime takedowns and seizures