Malware Distribution Network Takedowns
Biggest botnets are shrinking for the first time ever.

Botnets used to be a rounding error. In 2023, the largest one law enforcement tracked topped out at 136,000 infected devices. By 2024 that number crept to 228,000. Then in 2025 it jumped to 5.76 million, and by the first quarter of 2026 it hit 13.5 million devices, according to Cryptika. That's a hockey stick with a grudge.
Here's the part that actually matters, though: Q1 2026 marked the first quarter that number went down instead of up. That reversal is worth sitting with, because it's the earliest sign that coordinated, multi-phase law enforcement might be bending the whole curve.
Infostealers tell a similar story from a different angle. Reporting on 2024 malicious infrastructure found that malware-as-a-service infostealers led all infections that year, with LummaC2 sitting on top of the pile in terms of command-and-control servers observed. Between March and May of 2025 alone, Microsoft found more than 394,000 Windows machines worldwide infected by Lumma. The FBI eventually traced it back to roughly 10 million infections total.
And the distribution channels keep multiplying. The YouTube Ghost Network, a system of compromised accounts pushing malware through tutorial-style videos, saw its malicious video output triple in 2025 compared to prior years. One video alone, posing as an Adobe Photoshop tutorial, pulled in 293,000 views. This sits in search results next to actual Photoshop tutorials, waiting for someone to click.
Put those numbers together and the shift makes sense: law enforcement stopped chasing individual criminals years ago and started going after the pipes. The question this raises, and the one worth answering carefully, is whether tearing out pipes actually works when the plumbing can be rebuilt overnight.
What Operation Endgame actually dismantled across its three phases
Operation Endgame is the closest thing cybercrime enforcement has to a franchise, and it's been running long enough to have a plot arc.
Phase one landed May 27 to 29, 2024, coordinated out of Europol's headquarters. Targets included IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, and Trickbot, all droppers used to plant follow-on malware. More than 100 servers came down. Around 2,000 domains got seized globally. The malware families involved traced back to at least 15 ransomware groups. One arrest happened in Armenia, three in Ukraine, and eight suspects landed on Europe's Most Wanted list. France, Germany, and the Netherlands led the effort, backed by Europol, Eurojust, Denmark, the UK, and the United States.
Phase two split into two moves roughly a year apart. In April 2025, investigators turned Phase 1's seized data into actual arrests: customers of the Smokeloader pay-per-install botnet started getting knocks on the door, house searches, and "knock and talks" because their names sat in a database captured almost a year earlier. Then in May 2025, police seized 300 servers and 650 domains tied to Bumblebee, Latrodectus, QakBot, Hijackloader, DanaBot, TrickBot, and Warmcookie. Eurojust reported international arrest warrants against 20 people and more than €3 million in cryptocurrency seized.
Phase 3.0 came in November 2025, targeting the Rhadamanthys infostealer, the Elysium botnet, and the VenomRAT remote access trojan. More than 1,000 servers went down. A main suspect behind VenomRAT was arrested in connection with the operation. The dismantled infrastructure held several million stolen credentials, a huge win and a horrifying inventory count at once.
The sequencing here is the actual headline: infrastructure first, then customers, then more infrastructure. That progression shows seized data is a working asset investigators can return to months later. Alexandru Catalin Cosoi, chief security strategist at Bitdefender, which assisted on the operation, pointed out that the effort underscored how much private-public coordination matters at this scale. That's the mechanism that made the arrests in Phase 2 possible at all.
The LummaC2 takedown as a precise anatomy of what disruption looks like
If Operation Endgame is the franchise, the LummaC2 takedown is the tightly scripted episode where every beat lands exactly where it should, right up until the sequel undoes half of it.
On May 21, 2025, the Justice Department, Microsoft's Digital Crimes Unit, Europol's EC3, and Japan's Cybercrime Control Center all moved at once. A U.S. District Court in the Northern District of Georgia granted an order letting Microsoft seize and block roughly 2,300 malicious domains that formed Lumma's backbone. The DOJ took out the central command structure and the marketplaces where Lumma was sold. Europol and Japan handled the infrastructure sitting in their own jurisdictions.
Microsoft turned the domains into sinkholes, redirecting traffic to collect intelligence and shield victims still connected to infected machines. That made it an ongoing data source, not just a one-time disruption.
The scale of what Lumma had built is worth sitting with for a second. Lumma operated with thousands of paying customers spread across subscription tiers, essentially a SaaS pricing page for stealing browser credentials, banking logins, email, and crypto wallet seed phrases. At least 1.7 million information-stealing attacks used it.
Then came the part that should temper any celebration. Two domains were seized on May 19. By May 20, operators had stood up three new ones. Those got seized on May 21. What used to take criminal infrastructure weeks to rebuild took about two days, cat and mouse compressed into a sprint.
Reporting on the H1 2025 period shows LummaC2 did decline after the takedown. But by mid-July 2025, researchers spotted new domains tied to Lumma resolving to Cloudflare IP addresses, the same evasion tactic operators leaned on before any of this happened. And the YouTube Ghost Network data seals the point: Lumma had been the most distributed malware in that network before the disruption. Afterward, Rhadamanthys took its spot. Demand found a new vendor.
Why operators rebuild quickly and how they do it
Infrastructure is cheap. That's the whole secret, and it's widely understood.
A new domain costs next to nothing to register. Legitimate content delivery networks like Cloudflare absorb malicious traffic right alongside legitimate traffic, and blocking them wholesale would break half the internet's normal operations along with the bad stuff. So operators lean on that ambiguity. Recorded Future's 2024 report documented Russian state-sponsored groups doing exactly this: Ngrok, Cloudflare Tunnels, and Telegram all showed up as cover. One group, tracked as BlueDelta, shifted to Ngrok specifically after facing takedown pressure. Another, BlueAlpha, used Cloudflare Tunnels to stage a tool called GammaDrop. These aren't obscure criminal services. They're the same tools startups use to expose a local dev server to the internet.
LockBit is the textbook case for how fast a "dismantled" operation can walk it back. Operation Cronos, in February 2024, saw the FBI and NCA seize infrastructure and recover decryption keys — the NCA reported over 1,000 at the time of the operation, while the FBI separately identified more than 7,000 through its own investigation. LockBit was back within days. Its leader publicly taunted the FBI, claiming the takedown made the group stronger, according to Carbonite's 2024 Nastiest Malware report. The infrastructure came back fast enough to make the taunt land.
Structurally, affiliate-based malware-as-a-service models are built to survive exactly this kind of hit. When the central operator gets taken down, the affiliates, the people who actually knew the tactics, the customer lists, sometimes the code itself, don't retire. They migrate to whatever service is next in line.
That migration reshapes the whole market. Recorded Future's 2024 report points out that law enforcement action against RedLine Stealer, combined with LummaC2's own product development, helped drive Lumma's rise to the top spot. One competitor's takedown became another's growth opportunity. Latrodectus told a similar story: it accounted for a large share of all dropper and loader detections in 2024, rising as the dropper market shifted around it.
The pattern holds across every case: knock out one node, and demand redirects. Whatever tool survives gets better funded and more innovative almost overnight, because it just inherited a captive customer base with nowhere else to go.
What takedowns genuinely accomplish despite their limits
Takedowns deliver real results.
Microsoft's sinkholing of those 2,300 Lumma domains cut off roughly 394,000 identified infected machines from their command-and-control servers, even if only temporarily. That's real protection during a real window, and for the victims sitting inside that window, temporary protection still matters.
Seized data ages well, too. The Smokeloader customer database captured in May 2024 sat quietly for almost a year before it produced arrests in April 2025. Servers get torn down. Records don't expire the same way.
There's also a cost dimension that's easy to miss. That rapid scramble to rebuild Lumma's domains wasn't free for the operators. Every new domain they stood up was a fresh piece of infrastructure exposed to investigators, a fresh chance to leave a fingerprint. Forcing criminals into visible, rushed, traceable behavior has value even when it doesn't end the operation outright.
Arrests carry weight too, obviously. Operation Red Card picked up 306 suspects and seized 1,842 devices across seven African countries. Operation Serengeti 2.0 dismantled a network of roughly 1,000 people and clawed back $97.4 million from more than 88,000 victims. Losing personnel and losing money both cost something that a fresh domain registration can't undo.
And then there's that reversal in botnet growth heading into Q1 2026, the first downturn after years of relentless climbing. It's the strongest signal so far that sustained, coordinated operations can shift the aggregate trend rather than merely displacing a handful of bad actors from one server rack to another. Recorded Future's 2024 report also notes something less flashy but just as important: each operation adds to a growing base of international cooperation and investigative know-how. The next Operation Endgame benefits from everything the last one learned.
Where the gaps remain and what they mean for defenders
Fast-flux is the gap nobody's closed. CISA warned in April 2025, alongside partner agencies, that DNS-based fast-flux techniques (rotating domains rapidly across backend IP infrastructure) pose a genuine national security risk precisely because they're built to frustrate exactly the kind of domain seizure that made the Lumma takedown possible. Lumma's own pivot back to Cloudflare IPs in July 2025 is the same problem showing up in the wild, confirmed in the wild, beyond the April 2025 advisory.
Substitution timing matters more than most defenders give it credit for. Substitute tools moved quickly to fill the gap Lumma left behind. That means watching the malware that just got taken down tells a defender less than watching whatever's positioned to replace it.
Distribution keeps sprawling past the channels security teams are used to watching. The YouTube Ghost Network has reportedly been active since at least 2021, and its output tripled in 2025 alone. A video posing as an FL Studio tutorial pulled 147,000 views, second only to the Photoshop fake at 293,000. This is a consumer-platform problem now, sitting in the same search results as legitimate tutorials, a problem sprawling across consumer platforms that enterprise security teams can no longer treat as someone else's perimeter.
Recorded Future's H1 2025 data shows a tactical pivot underway too: after infostealers dominated H1 2024, remote access trojans like AsyncRAT, XWorm, and Remcos started gaining ground. Operators appear to be diversifying their toolkits in response to exactly the enforcement pressure described above.
None of this replaces basic patch discipline, either. Disclosed CVEs rose 16% from H1 2024 to H1 2025, and of the 161 vulnerabilities under active exploitation, nearly 69% needed no authentication at all and 30% allowed remote code execution, according to Recorded Future. Infrastructure takedowns leave that exposure entirely intact.
Put plainly: takedowns matter, but they mark a beginning rather than an end. Defenders who track infrastructure reconstitution, watch for the substitute product before it fully arrives, and keep patch hygiene separate from any hope that law enforcement will handle the network layer, are the ones actually converting a legal win into something that holds up past the next news cycle.
Sources
- Dissecting YouTube’s Malware Distribution Network - Check Point Research
- Top 10 Cyber Law Enforcement Operations of 2025
- Carbonite blog | Nastiest Malware of 2024
- 2024 Malicious Infrastructure Insights: Key Trends and Threats
- H1 2025 Malware and Vulnerability Trends
- eurojust.europa.eu
- europol.europa.eu
- cryptika.com


