
By Andréanne Bergeron, Security Researcher
Every few months, another headline announces a major cybercrime takedown: servers seized, domains sinkholed, arrests made.
Recent examples include Operation Magnus (targeting RedLine and META stealers in October 2024), Operation Endgame (targeting dropper infrastructure in May 2024), and the May 2025 FBI/DOJ/Europol/Microsoft action against LummaC2. These operations generate significant press coverage and signal meaningful institutional commitment to combating cybercrime. But what is their actual impact on the cybercrime ecosystem?
Key Findings on Law Enforcement Takedowns
- Most law enforcement takedowns fail to reduce cybercrime in the long term. While they often disrupt the targeted malware, criminal activity usually shifts to alternative infostealer families instead of disappearing.
- Cybercriminal ecosystems are resilient and adaptive. In several cases, overall stealer log volume actually increased after takedowns, indicating market displacement rather than suppression.
- Infrastructure seizures alone are not enough. Operations focused primarily on servers and domains had little lasting impact because threat actors quickly rebuilt infrastructure or migrated to competing malware.
- The FBI/LummaC2 operation was the only clear success. It reduced LummaC2 activity by 46% immediately and 39% after 90 days, while also decreasing overall infostealer activity across the ecosystem.
- Multi-layered disruption appears to be the key to success. The FBI/Lumma operation targeted not only infrastructure but also distribution channels, monetization, and criminal trust, suggesting that coordinated attacks on multiple parts of the cybercrime ecosystem are more effective than technical takedowns alone.
Identity Intelligence
Takedowns Displace Infostealers. Continuous Monitoring Catches What Follows.
When RedLine was disrupted, activity tripled elsewhere. When infrastructure is seized, operators migrate to competing families within weeks. Flare continuously collects stealer logs across dark web markets and Telegram channels, so your team detects exposed credentials regardless of which malware family is active this quarter.
Data and Methodology
At Flare, we collect stealer logs as part of our core mission: ensuring our clients know what credentials and sensitive data have been exposed. Our analysis for the present article draws on a corpus of approximately 44 million infostealer logs ingested into the Flare platform between June 2024 and June 2026, representing one record per compromised host. Logs were attributed to individual malware families using a combination of syntactic fingerprinting and telemetry-based classification. Daily log volume served as the primary outcome variable.

Direct Impact on Targeted Families
The results are shown in the table below. Statistically significant results (p < 0.05) are marked with “*”. Only one operation produced a statistically significant drop in its targeted family’s activity: the May 2025 FBI/DOJ/Europol/Microsoft action against LummaC2. LummaC2 volume fell 46% in the two weeks immediately following the operation (p = 0.042) and remained 39% below its pre-operation baseline over the following 90 days (p = 0.001). This is the strongest and most sustained suppression signal in the entire dataset.
Every other operation failed to significantly reduce its target. RedLine actually tripled in the 90 days following Operation Magnus (p = 0.045), which had specifically targeted it. LummaC2 grew 75% in the 90 days following Operation Secure (p = 0.004), which had also named it as a target. Rhadamanthys showed no measurable response to Operation Endgame Phase 3, largely due to its negligible volume in our dataset.

Total Market Impact
To assess whether law enforcement operations reduced total criminal activity or merely redistributed it, we computed aggregate daily stealer log volume across the observed intervention time frame. Results are summarized in the graph below, which displays the percentage change in total market volume relative to the pre-intervention baseline for each operation and time window.

The dominant pattern across the table is one of market growth following intervention. Three of the four operations show predominantly positive percentage changes, indicating that criminal activity displaced into other families rather than ceased. Operation Magnus produced a significant 70% market increase at ±90 days (p = 0.032), confirming that disrupting RedLine drove volume into the broader ecosystem. Operation Endgame Phase 3 is associated with a 41% market increase at the same horizon (p = 0.042), though this likely reflects background ecosystem growth rather than a direct operational effect, given Rhadamanthys’ negligible market share at the time.
The FBI/Lumma operation diverges sharply from this pattern. Total market volume contracted by 55% at ±14 days, 34% at ±30 days, 19% at ±60 days, and 38% at ±90 days, with the 90-day result reaching statistical significance (p = 0.011). It is the only intervention in our dataset that produced a net reduction in total market activity across all time windows. This is a finding that warrants closer examination of the structural features that distinguished it from prior operations.
What Made the FBI/Lumma Operation Different?
The FBI/Lumma action stands as a clear outlier in our dataset. Understanding why it succeeded where others did not requires looking beyond the scale of the operation to its structure.
Previous operations (Magnus, Secure, and Endgame Phase 3) primarily targeted technical infrastructure: servers, domains, and command-and-control nodes. This approach has a well-documented weakness. When infrastructure is seized but operators, affiliates, and source code remain intact, criminal activity relocates instead of stopping. Our data confirms this: in every case except FBI/Lumma, total market volume either held flat or grew in the months following the operation, as displaced activity migrated to competing families.
The FBI/Lumma operation disrupted the ecosystem at multiple layers simultaneously. Beyond seizing technical infrastructure, the coalition, which unusually included both law enforcement agencies and Microsoft, targeted the distribution channels and monetization mechanisms that LummaC2 depended on. This meant affiliates could not simply switch to a new server; the financial relationships and delivery pipelines that made the operation profitable were degraded at the same time.
The operation also appears to have inflicted significant reputational damage within the criminal ecosystem. In the aftermath, LummaC2 operators faced public accusations of exit scamming and law enforcement cooperation on closed forums. This outcome is a form of harm that is hard to recover quickly, since cybercriminal markets run on trust.
The lesson is straightforward: operations that hit a single layer of the criminal supply chain tend to displace activity rather than eliminate it. The FBI/Lumma action worked because it degraded the technical, financial, and reputational foundations of the ecosystem at the same time. That simultaneity, more than scale, appears to be the critical variable.
Recommendations for Security Teams
Do not assume a publicized takedown eliminates the threat. Even after major law enforcement operations, infostealer activity often persists through alternative malware families. Continue monitoring for credential exposure and stealer-related threats rather than treating a takedown as a resolution.
Focus on exposure-based defense rather than malware names. Detection and response strategies should prioritize indicators of compromise, credential theft, and account takeover risk instead of relying solely on tracking specific infostealer families that may quickly be replaced.
Expect threat actor adaptation following major operations. Significant takedowns can trigger shifts in the threat landscape. Security teams should increase vigilance in the weeks and months following major law enforcement actions, as criminal activity may be redistributed rather than reduced.
Maintain continuous credential monitoring. Because threat actors frequently migrate to new tools after disruptions, organizations should continuously monitor for exposed credentials, session cookies, and other compromised data rather than focusing on specific malware families.
Further Analysis to Strengthen Takedowns
Law enforcement operations against infostealer infrastructure typically displace criminal activity rather than eliminate it. Criminals migrate to alternative tools, and total market volume recovers or grows.
The FBI/Lumma action is the exception. It is the only operation in this dataset that produced both a direct suppression of its target and a net reduction in total market activity. Understanding what made it structurally different is the key question for anyone designing future disruption strategy.
Identity Intelligence
Takedowns Displace Infostealers. Continuous Monitoring Catches What Follows.
When RedLine was disrupted, activity tripled elsewhere. When infrastructure is seized, operators migrate to competing families within weeks. Flare continuously collects stealer logs across dark web markets and Telegram channels, so your team detects exposed credentials regardless of which malware family is active this quarter.
Study Design
We employed an interrupted time series (ITS) design which is a quasi-experimental approach commonly used to evaluate the impact of discrete policy interventions on longitudinal outcomes when randomization is not feasible. Each law enforcement operation was treated as an exogenous intervention, with the announced date of the operation serving as the interruption point.
For each operation, we defined symmetric pre- and post-intervention windows of ±14, ±30, ±60, and ±90 days. The pre-intervention window established the baseline distribution of daily log volume while the post-intervention window captured the outcome. The use of multiple time horizons allows us to distinguish between short-lived disruptions and sustained suppression effects.





