Elysium botnet is a malware-operated botnet that was publicly identified as a target of Europol-led Operation Endgame in 2025 alongside Rhadamanthys and VenomRAT. Available high-confidence reporting ties Elysium to criminal botnet infrastructure rather than a state-sponsored intrusion set. Confirmed public facts in this context are limited: its infrastructure was among systems seized or disabled during coordinated international law-enforcement action spanning multiple countries. No corroborated details are available here on its malware family lineage, operator identity, victimology, initial access methods, persistence mechanisms, monetization model, or whether it functioned primarily as a loader, remote-access platform, spam botnet, or other botnet subtype. Known aliases include Elysium and elysium_botnet.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Elysium botnet is a botnet infrastructure used for supporting credential theft, remote access, and cybercrime operations.
Elysium is a botnet used to control large numbers of infected devices, often for purposes such as credential theft, ransomware deployment, or cryptocurrency mining.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.