Trace team background

DISRUPTING THE UNDERGROUND

We're shutting down the threat actors

Bitsight TRACE works alongside law enforcement, government agencies, and global partners to disrupt malware operations, botnets, ransomware campaigns, and cybercriminal infrastructure. 

Real intelligence. Real impact. Real takedowns.

6

Threat actor operations disrupted

12+

Years of coordinated action

Impact on the underground

Each case represents intelligence, collaboration, and real-world impact against the cybercriminal economy.

Malware-as-a-Service

Amadey

Botnet, loader, RAT

Bitsight TRACE supported Europol and Microsoft with C2 infrastructure mapping, IoCs, real-time infection telemetry, and malware analysis. Domains and IP addresses were seized or disrupted.

Operation Endgame • June 2026

Read the story

Malware-as-a-Service

StealC

Infostealer

Bitsight TRACE contributed C2 mapping, IoCs, infection telemetry, malware analysis, and configuration extraction. The coordinated action targeted domains, IP addresses, and C2 infrastructure supporting StealC.

Operation Endgame • June 2026

Read the story

Malware-as-a-Service

Lumma Stealer

Infostealer

Bitsight collaborated with Microsoft's Digital Crimes Unit since mid-2024. Bitsight TRACE participated in coordinated action against malware operations, C2 infrastructure, and data sale channels. Microsoft's seizure notice identifies Bitsight as a partner.

Microsoft-Led Global Disruption • May 2025

Read the story

Botnet

Necurs

Botnet, malware dropper, spam delivery

Bitsight worked with Microsoft's Digital Crimes Unit beginning in 2017, contributing reverse engineering, malware analysis, infection telemetry, and C2 intelligence. The action disrupted botnets and was followed by mitigation and eradication.

Microsoft-Led Global Disruption • March 2020

Read the story

Botnet

Ramnit

Banking trojan and botnet

AnubisNetworks (Bitsight subsidiary since October 2014) worked with Europol, Microsoft, and Symantec. Cyberfeed intelligence provided botnet sizing, geographic distribution, C2 mapping, and aggregated telemetry.

Europol EC3-Led Takedown • February 2015

Historical

GameOver Zeus

Banking trojan and P2P botnet

AnubisNetworks worked with the UK National Crime Agency and FBI to track and profile C2 infrastructure. Cyberfeed intelligence supported the operation and successfully sinkholed and monitored the botnet.

Operation Tovar • June 2014

Taking the fight to the underground

Talk to us about how Bitsight TRACE monitors the underground, helps law enforcement and government agencies disrupt threats, and protects organizations, like yours, from emerging attacks.

 

Request demo