INTERPOL Crushes Global Cybercrime Ring: 20,000+ Malicious IPs Destroyed, 32 Arrested in Massive 26-Nation Takedown


# Global Cybercrime Crackdown: INTERPOL Dismantles 20,000 Malicious Domains in Major Operation

In a significant blow to cybercriminals worldwide, INTERPOL successfully dismantled over 20,000 malicious IP addresses and domains linked to 69 information-stealing malware variants during Operation Secure, a coordinated international effort spanning January to April 2025.

## Unprecedented International Cooperation

The operation brought together law enforcement agencies from 26 countries across the Asia-Pacific region, demonstrating the power of international collaboration in combating cybercrime. Participating nations worked together to identify malicious servers, map criminal networks, and execute precise takedowns.

The results were impressive: 79% of identified suspicious IP addresses were successfully neutralized, with authorities seizing 41 servers containing over 100 GB of criminal data. The operation also led to 32 arrests across multiple countries.

## Major Arrests and Seizures

Vietnam emerged as a hotspot for enforcement action, with authorities arresting 18 suspects and confiscating electronic devices, SIM cards, business documents, and $11,500 in cash. Sri Lanka followed with 12 additional arrests through targeted house raids, while Nauru apprehended two individuals.

Hong Kong Police made a particularly significant discovery, identifying 117 command-and-control servers distributed across 89 internet service providers. These servers served as central hubs for launching phishing campaigns, online fraud schemes, and social media scams.

## The Growing Threat of Information Stealers

Information-stealing malware represents a critical threat in today’s digital landscape. These malicious programs, often sold as subscription services on underground forums, harvest sensitive data including:

– Browser credentials and passwords
– Banking and credit card information
– Cryptocurrency wallet data
– Authentication cookies

Cybercriminals monetize this stolen information by selling it on dark web forums, enabling other threat actors to launch devastating follow-up attacks such as ransomware deployments, data breaches, and business email compromise schemes.

## Private Sector Partnership

The operation’s success was enhanced by collaboration with private cybersecurity firms. Singapore-based Group-IB provided crucial intelligence on accounts compromised by notorious stealer malware including Lumma, RisePro, and Meta Stealer.

“The compromised credentials and sensitive data acquired by cybercriminals through infostealer malware often serve as initial vectors for financial fraud and ransomware attacks,” explained Dmitry Volkov, CEO of Group-IB.

## Looking Ahead

Operation Secure follows recent successes, including the seizure of 2,300 domains associated with the Lumma Stealer malware. These coordinated efforts demonstrate the international community’s commitment to disrupting cybercriminal operations and protecting digital infrastructure.

As information stealers continue to evolve and proliferate, the success of Operation Secure serves as both a warning to cybercriminals and a blueprint for future international cooperation in the fight against digital crime.

Share This Article