A sprawling ransomware network that has extorted over ₹190 Crore (€21.2 million) from victims across the globe has been taken down in a law enforcement operation of record scale.
Multiple countries, including the UK, US, Germany, Netherlands, France, Canada and Denmark teamed up as part of the joint operation, dubbed “Operation Endgame”, alongside the support of Europol and Eurojust.
The operation, which took place between 19-22 May 2025, focused on the key infrastructure being used by cyber criminals to launch ransomware attacks and conduct other illicit activities.
Law enforcement were also able to seize around 300 servers and sinkhole 650 malicious internet domains which attackers used to launch attacks and control victim communications.
What’s more, the action week of Operation Endgame also saw the forfeiture of €3.5 million worth of cryptocurrency, accounting for more than €21.2 million of virtual currency seized throughout the entire operation. This substantial seizure is a serious hit against the illicit financial infrastructure of the ransomware network, he said.
Importantly, 20 alleged leading members of the ransomware syndicate, for whom international arrest warrants have been issued, have also been identified. These people are thought to play a role in facilitating the initial access into victims’ networks, while handling the follow-up ransomware deployment.
Significantly, 18 of these suspects have been put on the European Union’s Most Wanted list showing unmistakable commitment to pursue these criminals and bring them to justice.
This group leveraged notable malware strains such as Bumblebee, Latrodectus, QakBot, HijackLoader, DanaBot, TrickBot, and WARMCOOKIE. Such malware strains are usually sold as a service to other adversaries and lead to massive, debilitating ransomware operations.
By taking down the infrastructure behind these malware families, law enforcement has interrupted a key channel for ransomware”>ransomware attacks.
“This action represents a paradigm shift and in many ways, other law enforcement agencies and judicial authorities will be encouraged and inspired by these developments and will have new base to follow”, Catherine De Bolle, executive director, Europol said.“This new phase shows law enforcement working together across borders and demonstrates that no criminal is beyond our reach.
“By using the rule, the chain of events triggered by the takeover is interrupted, at the adversary’s foothold, before the attack is set in motion.
The action takes place following a similar major international operation against botnets in May 2024, and demonstrates law enforcement’s continued and adapted approach to try and shut down the persistent threat of ransomware.
The focus on “initial access malware” in this latest phase represents an attempt to stop cyberthreats in their tracks, and prevent ransomware groups from breaking in and locking down victims’ systems.
Although the takedown of this ₹190 Crore ransomware operation is a major win, security experts have warned that ransomware is still a menace. Organizations and users are also encouraged to adopt best practices, such as updating software, implementing strong password practices and training employees on how to identify and avoid phishing attempts. The work being done by global policing initiatives, as we see here from Operation Endgame, is an important shield in this battle.





