Top Infostealer Disrupted After Criminals Lose Server Access

Top Infostealer Disrupted After Criminals Lose Server Access

TechRadar
TechRadarNov 12, 2025

Companies Mentioned

Why It Matters

The disruption shows law‑enforcement can effectively dismantle cybercrime services, raising operational risk for attackers and potentially curbing the spread of infostealers. It also signals heightened scrutiny of MaaS platforms, impacting the broader cybercrime ecosystem and the security posture of targeted organizations.

Summary

The Rhadamanthys infostealer, a leading malware‑as‑a‑service platform, has been disrupted after German police reportedly accessed its web panels, locking out many criminal customers. Researchers noted the Tor site is offline and that SSH access now requires certificates, forcing users to reinstall or shut down servers. The takedown appears tied to Operation Endgame, a broader law‑enforcement campaign that recently seized hundreds of servers, domains and cryptocurrency assets. The incident underscores authorities’ growing capability to infiltrate and cripple MaaS infrastructure.

Top infostealer disrupted after criminals lose server access

Comments

Want to join the conversation?

Loading comments...