In a significant development following last year’s Operation Endgame, law enforcement agencies have detained at least five individuals identified as customers of the Smokeloader botnet. Europol announced today that the operation continues as investigators analyze data from over 100 servers seized during the initial phase, which targeted major malware operations including IcedID, Pikabot, Trickbot, Bumblebee, Smokeloader, and SystemBC.
The Smokeloader botnet, operated by a threat actor known as ‘Superstar,’ functioned as a pay-per-install service that granted customers access to compromised machines. According to Europol, “In a coordinated series of actions, customers of the Smokeloader pay-per-install botnet faced consequences such as arrests, house searches, arrest warrants or ‘knock and talks’.”
Cybercriminals used Smokeloader for various malicious activities, including:
– Deploying ransomware
– Running cryptominers
– Accessing victims’ webcams
– Logging keystrokes
A key breakthrough came when investigators seized a database containing registered Smokeloader customers, enabling them to link online aliases to real-world identities. Some suspects have cooperated with authorities, allowing examination of digital evidence on their personal devices.
To support ongoing investigations, Europol has established a dedicated website for sharing updates and has published animated videos explaining how officers are tracking down Smokeloader affiliates. The agency encourages anyone with information to contact authorities through the Operation Endgame website, which is also available in Russian.
Following last year’s takedown, sanctions were imposed against six individuals involved in cyberattacks targeting critical infrastructure in EU member states. Additionally, the U.S. Treasury sanctioned cryptocurrency exchanges Cryptex and PM2BTC, which were used by cybercrime groups, including Russian ransomware gangs, to launder funds.
