INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Seizes 53 DDoS Domains Exposing 3 Million Accounts
| 2026-04-17 05:46 LOW LOW DATA BREACH DDOS & DISRUPTION LAW ENFORCEMENT
Executive Summary
AI-generated
An international law enforcement operation, dubbed Operation PowerOFF, took down 53 DDoS domains and exposed over 3 million criminal user accounts on April 17, 2026. The action involved as many as 21 countries including Australia, Austria, Belgium, Brazil, Bulgaria, Denmark, Estonia, Finland, Germany, Japan, Latvia, Lithuania, Luxembourg, the Netherlands, Poland, Portugal, Sweden, Thailand, the U.K., and the U.S. Authorities disrupted access to DDoS-for-hire services by seizing technical infrastructure supporting them, hindering criminal operations and preventing further damage to victims. The operation targeted commercial distributed denial-of-service (DDoS) operations used by over 75,000 cybercriminals, with authorities sending warning emails and issuing 25 search warrants.
Technical Mitigations AI-generated
• Block or hunt for 'Booter services' that use servers, databases, and other technical components to facilitate DDoS-for-hire activities.
• Patch against the RapperBot botnet (version unknown) which was used in large-scale disruptive attacks targeting victims in over 80 countries since at least 2021.
• Detect and prevent DDoS activity that originates from well-resourced and skilled threat actors who rely on DDoS-for-hire services to customize or optimize their illicit activities.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation PowerOFF SeizesOperation PowerOFF SeizesOperation PowerOFFOperation PowerOFF
Target & Sectors
DACH
DACH
BENELUX
BENELUX
FIVE_EYES
FIVE_EYES
NORDICS
NORDICS
Incident Timeline
2026/04/17
Operation PowerOFF involved 21 countries participating in the seizure of 53 DDoS domains and exposure of 3 million criminal accounts.
Click on any entity below to view its context and source!
infrastructure
53 DDoS Domains
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts.
Apr 17, 2026
An international law enforcement operation, as part of Operation PowerOFF, seized 53 DDoS domains and exposed over 3 million criminal user accounts.
Click on any entity below to view its context and source!
infrastructure
53 DDoS Domains
Cybercrime
An international law enforcement operation has taken down 53 domains and arrested four people in connection with commercial distributed denial-of-service (DDoS) operations that were used by more than 75,000 cybercriminals.
victims
3 user accounts
The ongoing effort, dubbed
Operation PowerOFF
, disrupted access to the DDoS-for-hire services, took down the technical infrastructure supporting them, and obtained access to databases containing over 3 million criminal user accounts.
Tactical Metrics
Metrics
infrastructure
53
Ddos Domains
Click for context!
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts.
Cybercrime
An international law enforcement operation has taken down 53 domains and arrested four people in connection with commercial distributed denial-of-service (DDoS) operations that were used by more than 75,000 cybercriminals.
Metrics
victims
3,000,000
User Accounts
The ongoing effort, dubbed
Operation PowerOFF
, disrupted access to the DDoS-for-hire services, took down the technical infrastructure supporting them, and obtained access to databases containing over 3 million criminal user accounts.
Intelligence Sources
The Hacker News
2026-04-17
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T09:11
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
target region
Target Country
Australia
country
3x
tactic
Cyber Operation Type
Ddos
tactic
3x
organisation
Identified Entity
DDoS
entity
3x
timeline
Temporal Reference
August 2025
date
2x
general metric
Countries
21
countries
2x
campaign
Campaign
Operation PowerOFF Seizes
operation
Contextual Telemetry
Context Block
8 METRICS
tactic
MITRE ATT&CK Technique
T1584.001 - Domains
technique
infrastructure
Ddos Domains
53
ddos domains
general metric
Criminal Accounts
3,000,000
criminal accounts
general metric
Cybercriminals
75,000
cybercriminals
victims
User Accounts
3,000,000
user accounts
attribution
Attributing Entity
RapperBot
authority
general metric
Apr
17
apr
general metric
Search Warrants
25
search warrants
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.