Infostealer Malware Operations and Operator Arrests
RedLine's dominance collapsed after October takedown, but competitors instantly filled the void.

Infostealer malware runs on a rental model now. Someone builds the tool, someone else rents it, a third party sells whatever the tool steals, and none of them ever have to meet. Law enforcement has landed real hits against this system, most notably Operation Magnus and the Lumma disruption, but the arrests keep getting absorbed because the business itself was built to survive losing any one piece of it. That's the part worth sitting with: this isn't a story about whether enforcement works. The story is about why a working takedown and a thriving black market can both be true at the same time.
The mechanic to understand before anything else: infostealer-as-a-service (MaaS, malware-as-a-service) splits the work into three separate jobs. A developer writes and maintains the stealer. An affiliate pays a subscription — costs vary widely by tool and tier — and infects victims. A broker takes whatever got stolen and sells it. Each infected device produces a "log," a bundle of saved passwords, browser cookies, session tokens, autofill data, sometimes screenshots. SpyCloud's 2025 research put the average at 44 credentials and 1,861 cookies per device. That log lands on a dark web market or a Telegram channel within hours, sorted by which company it came from and what kind of access it unlocks. Arrest the developer, and affiliates just find a new tool. Arrest an affiliate, and the broker still has last week's inventory to sell. Three businesses, one supply chain, no single point of failure. It's a franchise model, basically. You can shut down one McDonald's. Good luck shutting down the concept of the hamburger.
The scale of the credential-theft problem law enforcement is trying to address
DeepStrike put 2025's number at 1.8 billion stolen credentials, pulled from 5.8 million infected devices. KELA counted 3.9 billion compromised credentials and 4.3 million infected devices the year before that. Verizon's 2025 Data Breach Investigations Report found stolen credentials involved in 32% of breaches worldwide, and 54% of ransomware victims had their domain credentials already sitting in an infostealer dump before the ransomware ever hit.
That last figure is the one to actually remember. Everything else is scale. That one is sequence: the theft happens, the log gets sold, and the ransomware crew that shows up weeks later is often just the second buyer in line, not the original thief.
Supply outpaced enforcement, plainly. The question this piece has to answer is whether any of the headline takedowns actually bent that trajectory, or just rerouted it.
How RedLine and META dominated, and what Operation Magnus actually seized
RedLine showed up in 2020 and became, by most measures, the most prolific infostealer in history. Kaspersky attributed 51% of all infostealer infections between 2020 and 2023 to it alone. By 2023, RedLine and its sibling family META together accounted for 57% and 27% of infections. Two tools running roughly 84% of an entire criminal market: that's a monopoly with a Telegram support bot.
Operation Magnus landed on October 28, 2024. Authorities from the U.S., U.K., Belgium, Portugal, Australia, and the Netherlands worked the case together through Eurojust, after Dutch National Police followed a lead from ESET. What they took was about as complete a seizure as this space gets: three servers, two domains, and reportedly the full source code for both RedLine and META, plus the license servers, the REST-API servers, the admin panels, and the Telegram bots running customer support. Belgian police detained two suspects on the ground. In the U.S., prosecutors unsealed a federal complaint against Maxim Rudometov, alleged to be RedLine's administrator, facing serious federal charges including conspiracy, computer intrusion, and money laundering.
Recorded Future found RedLine and META stole a combined 227 million credentials in 2024 alone. Source code, infrastructure, and a named operator facing decades in prison: that's the ceiling of what a takedown can look like. Nobody does better than that. What happened in the weeks after is the part that actually teaches you something.
What the market looked like within weeks of the Magnus takedown
The disruption was real, and it showed up fast. RedLine's share of infections fell from 57% to 13%. META dropped from 27% to 6%. Magnus looked like a clean win for about a quarter.
The market doesn't leave a vacuum sitting empty, though. LummaC2 jumped from under 1% of infections in 2023 to 31% in 2024, becoming the single most common stealer on earth almost overnight. RisePro climbed to 19.9%, StealC to 17.4%. Trend Micro spotted hundreds of new command-and-control URLs popping up within weeks of the RedLine and META servers going dark.
None of RedLine's former affiliates packed it in and found honest work. They moved to whatever tool had capacity, the same way a delivery driver switches apps the second one platform cuts its rates. That's the mechanism worth being blunt about: seizing a specific tool's servers displaces demand without destroying it. The credential economy just redistributed the same volume across whoever was left standing, and whoever was left standing had a 31% market share within a year.
Operation Endgame and the multi-phase approach to dropper infrastructure
Europol and Eurojust took a different swing with Operation Endgame, and the design shows they'd actually learned the Magnus lesson. Phase one, running May 27 through 29, 2024, hit dropper infrastructure across the U.S., Denmark, France, Germany, the Netherlands, and the U.K., targeting IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, and Trickbot all at once. More than 100 servers came down worldwide. Four people were arrested. One of them had reportedly earned at least €69 million in cryptocurrency just from renting out criminal infrastructure to other operators. That number alone tells you why someone rebuilds the server within a week of losing it.
Endgame kept going instead of stopping to take a bow. DanaBot and related services got hit in May 2025. Rhadamanthys, VenomRAT, and the Elysium botnet followed in November 2025. A June 2026 phase followed, recovering roughly 27 million stolen login credentials and seizing more than €41 million (around $47 million) in criminal cryptocurrency.
A related Smokeloader follow-up in 2025 shows the sharpest version of this strategy actually working. Police used a customer database seized during the initial takedown to connect online handles to real identities, and five more people were detained using intelligence from that seizure. The seized infrastructure became the evidence that unraveled the people running it, a meaningfully better outcome than a server simply going dark.
Needing five phases across two years to keep chasing the same layer of infrastructure is an admission of what this problem actually requires: a siege, sustained over time rather than a single raid.
The Lumma disruption and what happened to the market's dominant player
Lumma, also called LummaC2, showed up in mid-2022 and by 2024 had grabbed 31% of the infostealer market, the largest share of any single family tracked that year. It ran like an actual software company: tiered subscriptions, a customer dashboard, documentation, support, with pricing reported anywhere from a few hundred to over a thousand dollars a month depending on the tier. Hobbyist pricing at the low end, enterprise pricing at the high end. Crime, it turns out, has SKUs now.
Microsoft led a civil action against Lumma's infrastructure in May 2025. This one hit the market leader at the height of its share, which is the harder and more disruptive move than Magnus, which caught RedLine already sliding. Taking down the tool everyone's using right now beats mopping up a fading brand.
New infrastructure still showed up within days. Part of that speed is architectural, not just stubbornness: Lumma's affiliates run largely on their own delivery infrastructure, so knocking out the central command-and-control doesn't kill every campaign tied to it. The head comes off, but the limbs keep running for a while.
Why the MaaS structure absorbs arrests faster than enforcement can apply them
The developer, affiliate, and broker split is above all a defense mechanism built for exactly this kind of enforcement. Arrest a developer, and the other two nodes keep operating on schedule, untouched.
Analysis referenced in a piece for the Public Sector Network flags something worth watching: infostealer MaaS is drifting toward the same franchise structure ransomware-as-a-service already adopted. DragonForce takes a 20% cut while its affiliates run semi-independently underneath it. Infostealer operations are heading the same way, affiliates running their own branded operations on shared infrastructure they don't own and can't be blamed for losing.
Check Point adds a separate, uglier wrinkle: over 70% of infected devices are personal or BYOD, meaning most infections happen off any network a security team actually watches. The pipeline from infection to log-for-sale stays invisible until the credentials surface downstream, usually in someone else's incident report.
Franchising means arrested developers are replaceable, full stop. Affiliates already have the skills, the customer contacts, and the muscle memory to migrate to the next platform within days, sometimes hours. The Smokeloader case is the exception that proves the rule: when police capture the customer database instead of just the servers, they get a map of the affiliate layer itself, which is the exact thread multi-phase operations like Endgame are now built to pull. RedLine's collapse from 57% to 13% is real, and it proves arrests alone cannot out-sprint a structure engineered from day one to survive them.
What enforcement does accomplish, and where the limits are
Credit where it's due, and there's real credit to give. RedLine's fall from 57% to 13% — and META's parallel collapse — is a measurable dent, not a press release exaggeration. The June 2026 Endgame phase pulled back 27 million stolen credentials and seized €41 million in criminal funds. That is harm that didn't happen. The Smokeloader database seizure shows a well-timed takedown can turn into an intelligence operation instead of a one-time shutdown, yielding five more detentions off a single piece of evidence.
Enforcement leaves demand for stolen credentials intact, the log markets open, and an affiliate layer that relocates faster than a warrant gets drafted. Verizon's 54% figure, ransomware victims whose domain credentials were already sitting in an infostealer dump, says everything about the gap between a takedown and the rebuild that follows it. Breaches happen in that window. Every time. On a predictable clock that enforcement, so far, hasn't managed to break.
Sustained, multi-phase pressure (the Endgame model) beats single strikes, because it forces the ecosystem to keep rebuilding instead of catching its breath. But the honest ceiling is this: these operations raise the cost and the hassle of running a stealer service. The credential economy sitting in log markets and Telegram channels right now, priced and ready to buy, stays open whether or not anyone gets arrested next month.
Defenders must build their own response rather than waiting for the next Magnus or the next Endgame phase. Credential monitoring, endpoint detection tuned to actual stealer behavior, multi-factor authentication everywhere it can go, and treating every BYOD device as a permanent blind spot rather than an edge case: that's the realistic response to a threat enforcement can slow but never switch off. The top three stealer families in 2024 weren't the top three in 2025, and won't be in 2026 either, so tracking who's winning market share matters just as much as tracking who got arrested, which is the kind of live-threat-intelligence work that a specialist cybersecurity content studio like Cyberou grounds its reporting in.
Sources
- Infostealer Malware in 2025: Credential Theft at Scale
- Infostealer Malware and the Cartelisation of Cybercrime
- Infostealers: The Malware Behind the Credential Economy
- The Rise of Infostealers: Insights from 2024 - TwilightCyber
- Top Infostealers in 2026: How They Work and How to Stop Them
- Infostealers Stole 1.8B Credentials in 2025 [2026]
- usa.kaspersky.com
- recordedfuture.com


