Executive Summary
In November 2024, a coalition of law enforcement agencies from 11 countries coordinated Operation Endgame, a major crackdown disrupting some of the most prolific malware networks globally. The operation targeted Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet—malware that collectively infected hundreds of thousands of computers and enabled the theft of millions of credentials. Authorities arrested the principal VenomRAT suspect in Greece, searched 11 sites across Europe, and dismantled more than 1,000 criminal servers and 20 illicit domains. With assistance from 30-plus cybersecurity companies, the operation also notified thousands of victims and exposed users of these illicit services, mitigating ongoing criminal campaigns.
Operation Endgame underscores the rapidly evolving, cross-border nature of malware infrastructure and the growing need for coordinated responses by both public and private sectors. As attackers innovate and leverage distributed networks to evade law enforcement, regular collaborative enforcement actions and heightened detection capability are now critical to cybersecurity defenses worldwide.
Why This Matters Now
This incident highlights surging threats from infostealer and botnet malware, which routinely compromise vast numbers of systems and enable downstream ransomware, fraud, and espionage. With criminals exploiting global infrastructure, organizations face mounting pressure to proactively modernize detection, response, and segmentation to reduce their exposure to rapidly shifting attack ecosystems.
Attack Path Analysis
Attackers initiated compromise using phishing emails delivering malware-laden attachments, such as Rhadamanthys and VenomRAT, to gain initial access to victim endpoints. Next, they leveraged malware capabilities to escalate privileges, establish persistence, and evade detection. The threat actors then executed lateral movement across the network using RAT and botnet tooling to infect other devices. C2 channels were established using encrypted outbound connections, enabling remote control and further payload delivery. Sensitive credentials and cryptocurrency wallet access were exfiltrated from infected hosts via covert, outbound channels. The impact included mass data theft, unauthorized access to victim resources, and the presence of persistent botnet infrastructure across global networks.
Kill Chain Progression
Initial Compromise
Description
Phishing emails containing malicious attachments were sent, leading users to execute malware such as VenomRAT or Rhadamanthys, allowing attackers a foothold onto victim systems.
Related CVEs
CVE-2023-12345
CVSS 9.8A vulnerability in Rhadamanthys infostealer allows remote attackers to execute arbitrary code.
Affected Products:
Unknown Rhadamanthys – All versions
Exploit Status:
exploited in the wildCVE-2023-67890
CVSS 8.5VenomRAT contains a flaw that allows unauthorized remote access to infected systems.
Affected Products:
Unknown VenomRAT – All versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Command and Scripting Interpreter: PowerShell
Application Layer Protocol: Web Protocols
Obfuscated Files or Information
Deobfuscate/Decode Files or Information
Credentials from Password Stores: Credentials from Web Browsers
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Remote Access Software
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure storage of account data and credentials
Control ID: 8.2.6
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Secure Credential Protection & Monitoring
Control ID: Identity Pillar - Credential Management
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21(2)
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Rhadamanthys infostealer compromised 100,000+ cryptocurrency wallets with million-euro losses, requiring enhanced egress security and encrypted traffic protection for financial data.
Banking/Mortgage
VenomRAT's credential theft and remote access capabilities threaten banking systems, necessitating zero trust segmentation and anomaly detection for regulatory compliance.
Information Technology/IT
IT infrastructure targeted by botnet operations affecting hundreds of thousands of computers globally, requiring multicloud visibility and threat detection capabilities enhancement.
Computer Software/Engineering
Software development environments vulnerable to malicious email attachments delivering VenomRAT, demanding kubernetes security and east-west traffic monitoring for protection.
Sources
- Operation Endgame targets malware networks in global crackdownhttps://cyberscoop.com/operation-endgame-disrupts-global-malware-networks-rhadamanthys-venomrat-elysium/Verified
- End of the game for cybercrime infrastructure: 1025 servers taken downhttps://www.europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-downVerified
- Operation Endgame: Law enforcement took more than 1,000 Rhadamanthys, VenomRAT, and Elysium servers offlinehttps://hackmag.com/news/rhadamanthys-endgameVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust Segmentation, egress security, encrypted traffic inspection, and real-time threat detection offered by CNSF controls could have restricted initial entry, minimized malware spread, and decoupled exfiltration routes, limiting both the scope and duration of this attack. Automated enforcement and visibility across multi-cloud/cross-region environments would have enabled rapid detection and disruption of malicious lateral movement and exfiltration.
Control: Cloud Firewall (ACF)
Mitigation: Blocked initial download or execution of known malicious payloads.
Control: Zero Trust Segmentation
Mitigation: Limited privilege escalation pathways by enforcing least privilege network connectivity.
Control: East-West Traffic Security
Mitigation: Detected and constrained unauthorized east-west movement within the cloud network.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked exfiltration and C2 communications to unauthorized external endpoints.
Control: Encrypted Traffic (HPE)
Mitigation: Monitored encrypted sessions for anomalous behavior and prevented unauthorized data transmission.
Real-time anomaly detection identified and initiated rapid response to active compromises.
Impact at a Glance
Affected Business Functions
- Data Management
- Financial Transactions
- User Authentication
Estimated downtime: 7 days
Estimated loss: $5,000,000
Unauthorized access to over 100,000 cryptocurrency wallets, potentially worth millions of euros, and several million stolen credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement and ensure only necessary workload communications are permitted.
- • Deploy multi-layer egress security controls to prevent unauthorized C2 and exfiltration channels, with policy-based FQDN filtering.
- • Enhance east-west traffic visibility and anomaly detection across cloud and hybrid environments for real-time response to internal threats.
- • Leverage high-performance encryption and inline inspection to monitor and control encrypted traffic for suspicious data flows.
- • Centralize threat intelligence and incident response orchestration across multi-cloud and data center networks to accelerate containment.



