Operation Endgame Strikes at the Heart of Crypto Malware in an Unprecedented Global Crackdown
The FBI seizes 1,025 servers in a global operation targeting crypto-stealing malware networks like Rhadamanthys and VenomRAT.
The FBI has delivered one of its most consequential blows against cybercrime with a sweeping international campaign designed to cripple the malware networks draining cryptocurrency wallets worldwide. Known as Operation Endgame, this coordinated action dismantled the infrastructure behind some of the most aggressive threats targeting digital assets, seizing 1,025 servers and disrupting the systems that enable large-scale credential theft.
Launched in May 2024, the initiative unites law enforcement from more than a dozen countries across Europe, North America, and the Asia-Pacific region. Unlike earlier operations focused on individual cybercriminals, Endgame zeroes in on the physical backbone of malware distribution—servers, command-and-control centers, and bulletproof hosting providers that keep infostealers and botnets running. This structural approach is designed to inflict long-lasting damage on criminal ecosystems that have become increasingly sophisticated and decentralized.
Central to the latest phase were three notorious strains: Rhadamanthys, VenomRAT, and Elysium. Rhadamanthys operates as a subscription-based infostealer favored by phishing groups for extracting wallet credentials, seed phrases, and exchange logins with alarming efficiency. VenomRAT provides remote access capabilities, giving attackers live visibility into compromised systems. Elysium, a stealthy botnet, deploys cryptomining payloads while distributing additional malware. Together, these tools have facilitated billions in stolen assets, contributing to a surge in wallet-drain attacks over the last two years.
The FBI reports that dismantling the servers controlling these networks immediately halted thousands of active campaigns. Cybersecurity analysts estimate that similar disruptions have reduced infostealer activity by as much as 40% in affected regions, offering temporary but meaningful relief to users in the U.S., Europe, and Asia. Gregory Heeb, the FBI’s Deputy Assistant Director, underscored the scale of the threat, noting that these operations “target the backbone of cybercrime, making it harder for thieves to operate and giving victims a fighting chance.”
Operation Endgame aligns with broader U.S. efforts to counter criminal groups exploiting cryptocurrency. The newly formed Scam Center Strike Force has recovered over $401 million tied to Southeast Asian scam compounds and syndicates operating out of regions like Burma and Bali. These networks often use the same infostealer infrastructure targeted under Endgame, creating a strategic overlap that strengthens both operations.
The multinational nature of the takedown reflects growing geopolitical alignment around combating cyber threats. Authorities in Germany, France, the Netherlands, the U.K., and Australia coordinated arrests, server seizures, and domain takedowns, demonstrating a shared recognition that cryptocurrency-related cybercrime increasingly crosses borders and requires joint action.
For everyday users, the operation serves as both a relief and a reminder. While infrastructure disruptions weaken malware networks, cybercriminals are known for adapting quickly. Analysts warn that new variants, new hosting providers, and new phishing campaigns will inevitably emerge. Security agencies continue to advise individuals to adopt hardware wallets, enable two-factor authentication, avoid suspicious downloads, and regularly scan devices for infections.
Operation Endgame represents a turning point: a coordinated and methodical attempt to undermine digital theft at its most fundamental level. As blockchain adoption expands and the crypto market surpasses the $2 trillion mark, such actions will be indispensable for building trust in an increasingly interconnected financial ecosystem.



