From 19–22 May 2025, Eurojust and Europol coordinated an international operation, known as ‘Endgame 2.0’, targeting seven major malware variants: Bumblebee, Lactrodectus, HijackLoader, DanaBot, Trickbot, Qakbot, and WarmCookie. The operation involved law enforcement agencies from Germany, France, the Netherlands, Denmark, the UK, the US, and Canada, and resulted in international arrest warrants for 20 individuals, the takedown of over 300 servers, the seizure of €3.5m in cryptocurrency, and the neutralisation of 650 domains. This action follows Operation Endgame from May 2024, bringing the total value of cryptocurrency seized to €21.2m. Several key suspects are now subject to international and public appeals, with German authorities set to add 18 suspects to the EU Most Wanted list as of 23 May 2025.