Europol takes down 1,025 servers behind the Rhadamanthys infostealer

Reading Time: 5 min
18
techkahwa.net | 14 November 2025

European police have knocked out a large chunk of the infrastructure behind three well-known malware families, including the Rhadamanthys infostealer. Europol says 1,025 servers were taken down in the latest phase of Operation Endgame, which wrapped up today. If you have ever installed a cracked app or a “free” copy of paid software, this story is worth five minutes of your time.

What happened

Europol says that “between 10 and 14 November 2025, the latest phase of Operation Endgame was coordinated from Europol’s headquarters in The Hague.” The operation went after three targets:

  • Rhadamanthys, an infostealer, meaning malware built to quietly copy passwords, browser sessions and other credentials from an infected computer.
  • VenomRAT, a remote access trojan that lets criminals control a victim’s machine from afar.
  • Elysium, a botnet, which is a network of infected computers controlled as a group.

According to The Hacker News, investigators also seized 20 domains. Europol added that “the main suspect for VenomRAT was also arrested in Greece on 3 November 2025,” about a week before the main action began. Europol has not published the suspect’s name.

The scale is the part that stayed with me. In Europol’s words, reported by The Hacker News: “The dismantled malware infrastructure consisted of hundreds of thousands of infected computers containing several million stolen credentials.” The Hacker News also reports that the Rhadamanthys suspect had access to about 100,000 cryptocurrency wallets.

Who is affected

The people most directly affected are the owners of those hundreds of thousands of infected computers. Most of them probably have no idea. Infostealers are designed to stay invisible: they grab what they can and send it to the operator, often without slowing the machine down or showing any warning.

The most common way in is software that looks like a bargain: cracked versions of paid programs, game cheats, or “free” downloads of tools that normally cost money. The user thinks they are getting a deal, and the installer carries the malware along with it.

The stolen data then feeds other crimes. A saved email password can lead to account takeover. A stolen work login can be the first step in a ransomware attack on a company. That is why taking down infostealer infrastructure protects people who never installed anything suspicious themselves.

By the numbers

Item Figure Source
Servers taken down 1,025 Europol
Domains seized 20 The Hacker News
Action dates 10 to 14 November 2025 Europol
Malware families targeted 3 (Rhadamanthys, VenomRAT, Elysium) Europol
VenomRAT suspect arrested 3 November 2025, Greece Europol
Crypto wallets the Rhadamanthys suspect could access About 100,000 The Hacker News
Infected computers Hundreds of thousands Europol, via The Hacker News

What to do now

These steps follow general malware guidance from Europol and the US Cybersecurity and Infrastructure Security Agency (CISA).

  1. Stop downloading cracked software or “free” versions of paid apps. They are one of the most common ways infostealers reach ordinary users.
  2. Update your operating system and antivirus, then run a full scan of your computer.
  3. If you suspect an infection, change your passwords from a different, clean device. Start with your email account, because email is the key that resets everything else, then move to banking and crypto accounts.
  4. Turn on multi-factor authentication (MFA) for your important accounts, and use the option to log out of all sessions so any stolen browser sessions stop working.

A small note from my side: changing passwords on the same infected computer does not help much, since the malware can simply capture the new ones. Clean the device first, or use another one.

Why it matters

Infostealers rarely make headlines on their own. They sit at the start of the chain, and the damage shows up later as a hijacked account, an emptied wallet or a company hit by ransomware. Operations like Endgame aim at that first link, which is why their effect reaches far beyond the suspects involved.

A takedown is not a cure, and criminals do rebuild. Still, losing more than a thousand servers at once costs them time and money, and it dents their standing with their own customers. For the rest of us, the best protection is the boring one. Skip pirated software and keep your devices updated. And treat your email password as the most valuable password you own.

Sources

  • Europol, press release on the latest phase of Operation Endgame and the 1,025 servers taken down, November 2025, https://www.europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-down
  • The Hacker News, report on Operation Endgame dismantling Rhadamanthys, VenomRAT and Elysium infrastructure, November 2025, https://thehackernews.com/2025/11/operation-endgame-dismantles.html