Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
    SpaceX IPO: Kraken, Bybit, Coinbase, & Binance Lead the Crypto Rush
    SpaceX IPO: Kraken, Bybit, Coinbase, & Binance Lead the Crypto Rush
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

FBI and Global Agencies Take Down Crypto-Stealing Botnets

The operation seizes 1,000+ servers and cripples malware networks behind credential theft and crypto drainers.

Written By:
Thales Rodrigues

Reviewed By:
Jahnu Jagtap

Last updated: November 17, 2025 11:19 AM
Published 2025-11-15
Share
FBI and Global Agencies Take Down Crypto-Stealing Botnets

Key Highlights

  • The FBI and allies seized 1,025 servers tied to crypto-stealing malware.
  • Major strains taken down: Rhadamanthys, VenomRAT, Elysium.
  • It is part of a wider U.S. crackdown on global scam and fraud networks.

The U.S. Federal Bureau of Investigation (FBI) and international law enforcement partners have carried out one of their largest cybercrime disruptions of the year, dismantling malware networks that have been quietly raiding crypto wallets, browser credentials, and financial accounts across the globe.

The agency announced that Operation Endgame, a multinational effort launched in May 2024, took down 1,025 servers, seized 20 domains, and led to an arrest in Greece. This marks the third major takedown tied to the ongoing initiative.

Cyber tools on target

The targets of the operation were Rhadamanthys, a commercial-grade infostealer sold as malware-as-a-service, VenomRAT, a remote access Trojan used for surveillance and credential harvesting, and Elysium, a stealth botnet known for deploying cryptomining payloads and distributing additional malware.

These tools have been at the center of a surge in crypto wallet drains, credential hijacking, and large-scale financial fraud. Rhadamanthys, in particular, is designed specifically to vacuum up seed phrases, wallet files, browser auto-fills, exchange logins, and system data, a common choice for phishing crews and Telegram-based drainer ops.

Global operation targets cybercrime networks

The FBI executed the takedown alongside authorities in Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, and the UK, targeting the infrastructure that cybercriminals depend on to automate attacks.

The FBI and our partners successfully dismantled an infostealer, remote access trojan, and botnet as part of Operation Endgame. This marks the third large-scale action in this ongoing initiative, which was launched to combat criminal infrastructure used for ransomware attacks… pic.twitter.com/cjM0QYZpKl

— FBI (@FBI) November 14, 2025

They also seized command-and-control nodes used to manage infected machines, which is expected to disrupt thousands of active malware campaigns.

A broader crackdown on crypto-driven crime

The botnet takedown follows the launch of the Scam Center Strike Force, a new U.S. initiative focused on dismantling Southeast Asian scam compounds and Chinese-linked criminal networks that deploy similar infostealers. The task force has already seized $401.6 million in crypto, filed forfeiture actions for another $80 million, and coordinated arrests in Bali and Burma.

“The impact on victims is devastating,” said FBI Deputy Assistant Director Gregory Heeb. “Our job is to stop these criminals, and with global cooperation, we will.”

What comes next

The FBI says more coordinated actions are coming as agencies shift from chasing individual hackers to dismantling the infrastructures, such as servers, domains, and distribution systems, behind global crypto crime. Future phases of Operation Endgame will target malware developers, hosting providers, and botnet operators.

The agency also warns crypto users to treat any unauthorized access, drained accounts, or odd browser behavior as a sign of device compromise, and to migrate wallets and reset credentials immediately.

Also read: Leaked Emails Reveal Epstein Helped Fund MIT’s Bitcoin Work

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Thales Rodrigues- Crypto Journalist
By Thales Rodrigues
Follow:
Thales is a Brazilian economist passionate about marketing, bringing with him experience from the country’s largest banks and financial institutions. Outside of work, he dedicates his time to sports, family, and business studies.
Jahnu Jagtap - Crypto Research Analyst at The Crypto Times
By Jahnu Jagtap
Follow:
Jahnu Jagtap is a Research Analyst with over 5 years of experience in crypto, finance, fintech, blockchain, Web3, and AI. He holds a BSc in Mathematics and is certified in Blockchain and Its Applications (SWAYAM MHRD), Cryptocurrency (Upskillist), and NISM Certifications. Jahnu specializes in technical, on-chain, and fundamental analysis, while also closely tracking global macro trends, regulations, lawsuits, and U.S. equities. With a strong analytical background and editorial insight, he drives content that delivers clarity and depth in the fast-evolving world of digital finance.

Latest News

Ripple Bets on Flutterwave to Scale RLUSD Across Africa
Ripple Bets on Flutterwave to Scale RLUSD Across Africa
Kevin Warsh’s First FOMC Meeting Has 99.6% Odds of No Rate Change
Kevin Warsh’s First FOMC Meeting Has 99.6% Odds of No Rate Change
Indians Get a Regulated Route to US Crypto Stocks via GIFT City — But Bitcoin ETFs Stay Blocked
Indians Get a Regulated Route to US Crypto Stocks via GIFT City, Leaves Bitcoin ETFs Out
China Onboards 26 Banks for Cross-Border Digital Yuan Network
China Onboards 26 Banks for Cross-Border Digital Yuan Network
Robinhood Cuts 10% of Staff, Eliminating 290 Roles in Restructuring
Robinhood Cuts 10% of Staff, Eliminating 290 Roles in Restructuring

Find Us on Socials

You may also like

SkyAI Token Rockets 30% Past $0.41 Amid Acquisition Buzz

SkyAI Token Rockets 30% Past $0.41 Amid Acquisition Buzz

Retail Couldn't Buy SpaceX, So They Traded $9 Billion of It on Binance

Retail Couldn’t Buy SpaceX, So They Traded $9 Billion of It on Binance

South Korea Arrests 56 in USDT Laundering Ring Tied to Cambodia Scam Network

South Korea Arrests 56 in USDT Laundering Ring Tied to Cambodia Scam Network

Bitget CEO & Crypto Investor Clash Over Republic and SpaceX Access

Bitget CEO & Crypto Investor Clash Over Republic and SpaceX Access

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information