{"id":58799,"date":"2025-06-11T00:00:00","date_gmt":"2025-06-11T00:00:00","guid":{"rendered":"urn:uuid:59653923-9aae-54c0-9d79-5c5f8d6cbb6d"},"modified":"2025-06-11T00:00:00","modified_gmt":"2025-06-11T00:00:00","slug":"operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/","title":{"rendered":"Operation Secure: Trend Micro&#8217;s Threat Intelligence Fuels INTERPOL&#8217;s Infostealer Infrastructure Takedown\u202f"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/interpol-opsecure-thumbresized:Large?qlt=80\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"description\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"latest news,articles, news, reports,cyber crime\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2025-06-11\"> <meta property=\"article:tag\"> <meta property=\"article:section\" content=\"latest news\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/f\/interpol-operation-secure.html\"> <title>Operation Secure: Trend Micro&#8217;s Threat Intelligence Fuels INTERPOL&#8217;s Infostealer Infrastructure Takedown\u202f | Trend Micro (US)<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\">\n<link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendmicro\/clientlibs\/trendmicro-core-2\/clientlibs\/header-footer.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/f\/interpol-operation-secure.html\"><br \/>\n<meta property=\"og:title\" content=\"Operation Secure: Trend Micro's Threat Intelligence Fuels INTERPOL's Infostealer Infrastructure Takedown\u202f\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/interpol-opsecure-thumbresized.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Operation Secure: Trend Micro's Threat Intelligence Fuels INTERPOL's Infostealer Infrastructure Takedown\u202f\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/interpol-opsecure-thumbresized.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"50.676490288011\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layers *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"227523500\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"9.5\">\n<div class=\"article-details\" role=\"heading\" readability=\"39\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__description\">In this blog, we discuss how Trend Micro played a pivotal role in Operation Secure, a multi-national law enforcement effort that dismantled the infrastructure behind widespread infostealer malware campaigns across Asia and the Pacific.<\/p>\n<p class=\"article-details__author-by\">By: Joshua Paul Ignacio <time class=\"article-details__date\">June 11, 2025<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<div class=\"article-details__icons\"> <!--Add This--> <\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\"> <a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\" class=\"svg-icon\" alt=\"Share\"> <\/a> <a class=\"a2a_button_print addthis_link\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\" class=\"svg-icon\" alt=\"Print\"> <\/a> <\/div>\n<p> <!--Add to Folio--> <!--Subscribe--> <\/div>\n<\/div><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"> <\/p>\n<div class=\"richText\" readability=\"46.214175950826\">\n<div readability=\"37.766423357664\">\n<p><b>Key takeaways:<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Trend Micro was a key private sector partner in Operation Secure, a multi-country initiative that disrupted infostealer malware campaigns and enabled law enforcement agencies to take down over 20,000 malicious IPs and domains and arrest of involved cybercriminals.<\/span><\/li>\n<li>&nbsp;<\/li>\n<li><span class=\"rte-red-bullet\">The collaborative effort saw the seizure of 41 criminal servers and more than 100 GB of critical cybercrime data and proactively notified over 216,000 victims to facilitate swift protective actions.<\/span><\/li>\n<li>&nbsp;<\/li>\n<li><span class=\"rte-red-bullet\">Trend Micro leveraged its advanced global threat telemetry and provided actionable intelligence and malware analysis, contributing to a 79% removal rate of suspicious IP addresses and strengthening cyber defense efforts in the Asia-Pacific region.<\/span><\/li>\n<li>&nbsp;<\/li>\n<li><span class=\"rte-red-bullet\">Our investigations also revealed Vidar, Lumma Stealer, and Rhadamanthys as some of the most prominent infostealer families detected in this operation. We provide an overview and related reading to these infostealers in the blog.<\/span><\/li>\n<\/ul>\n<p>Trend Micro was part of the recently concluded <a href=\"https:\/\/www.interpol.int\/News-and-Events\/News\/2025\/20-000-malicious-IPs-and-domains-taken-down-in-INTERPOL-infostealer-crackdown\" target=\"_blank\">Operation Secure<\/a> that successfully disrupted the infrastructure behind widespread infostealer malware campaigns throughout Asia and the Pacific.&nbsp;<\/p>\n<p>The multi-country initiative brought together law enforcement agencies and experts from 26 countries and took down over 20,000 malicious IP addresses and domains, seized 41 criminal servers and more than 100 GB of data, and arrested 32 individuals linked to cybercrime. Operation Secure was conducted from January to April 2025 and together with law enforcement, where over 216,000 victims were notified to enable rapid protective countermeasures.&nbsp;<\/p>\n<p>We provided crucial intelligence and malware analysis as one of the operation\u2019s three private sector partners, leveraging our extensive global threat telemetry to produce detailed and actionable data that enabled law enforcement to identify malicious servers and pinpoint criminal infrastructure. The successful operation recorded a remarkable 79% removal rate of identified suspicious IP addresses.&nbsp;<\/p>\n<p>Hong Kong law enforcement analyzed over 1,700 intelligence leads and identified 117 command-and-control (C&amp;C) servers across 89 hosting providers identified as being used for phishing and fraud activities.&nbsp;<\/p>\n<p>Meanwhile, Vietnamese authorities arrested 18 suspects and seized devices and SIM cards linked to account fraud schemes. Police force in Sri Lanka and Nauru also conducted house raids, arresting 14 individuals and identifying 40 victims.<\/p>\n<p>These actions illustrate how server identification drives both tactical disruption and strategic arrests in multinational cybercrime operations.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/25\/f\/interpol-operation-secure\/interpol-opsecure-fig1.jpg\" alt=\"Figure 1. Operation Secure by the numbers. Image source: INTERPOL.\"> <\/p>\n<p><figcaption>Figure 1. Operation Secure by the numbers. Image source: INTERPOL.<\/figcaption><\/p>\n<\/figure><\/div>\n<div>\n<div class=\"richText\" readability=\"47.417539988969\">\n<div readability=\"40.502482073911\">\n<p><span class=\"body-subhead-title\">Targeting rising infostealer activities<\/span><\/p>\n<p>With INTERPOL at the helm, our experts specifically identified malicious servers utilized for deployment and C&amp;C communications by infostealers and other malware campaigns. These servers are core infrastructures that serve as the backbone of cybercriminal operations and identifying them is critical for law enforcement takedowns. These servers control infected devices, exfiltrate and store stolen data, and deliver additional malware payloads. By mapping and seizing these servers, law enforcement agencies were able to disrupt operations at scale, gather forensic evidence, and trace threat actors.<\/p>\n<p>The identification of these servers also facilitated real-time victim alerts, and the operation improved threat intelligence for long-term cybercriminal activity disruption and strengthened global coordination.<\/p>\n<p>Our investigations into these malicious servers also uncovered which infostealer families were most active as either deployed from or communicating with the compromised servers. The next sections give an overview of the infostealer families found to be prominent in this operation. We also provide links for more information and further reading.<\/p>\n<p><b>Vidar<\/b><\/p>\n<p>Vidar is a prevalent Malware-as-a-Service (MaaS) that has been active since 2018. Vidar is capable of exfiltrating sensitive data like browser credentials, cookies, and cryptocurrency wallets. It commonly spreads through malvertising, phishing, and cracked software, and can also act as a loader for other malware, including ransomware. Trend\u2122 Research,h in an investigation, revealed its distribution via <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/e\/tiktok-videos-infostealers.html\">social media<\/a>.\u202fWe have also previously observed samples that suggest that the cybercriminals behind this infostealer have tried to shift and use their tactics and techniques to deliver <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/i\/redline-vidar-first-abuses-ev-certificates.html\">ransomware<\/a>. &nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/25\/f\/interpol-operation-secure\/interpol-opsecure-fig2.png\" alt=\"Figure 2. Vidar infostealer\u2019s observed infection chain\"> <\/p>\n<p><figcaption>Figure 2. Vidar infostealer\u2019s observed infection chain<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32.120689655172\">\n<div readability=\"13.034482758621\">\n<p><b>Lumma Stealer (LummaC2)<\/b><\/p>\n<p>This rapidly growing infostealer-as-a-service gained notoriety in late 2022 and became one of the most active families in 2025. Lumma Stealer specializes in stealing browser credentials, crypto wallets, and autofill data. This infostealer often leverages public platforms like <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/a\/lumma-stealers-github-based-delivery-via-mdr.html\">GitHub<\/a> and content delivery networks for stealthy payload delivery, but has also been observed to abuse <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/j\/beware-lumma-stealer-distributed-via-discord-cdn-.html\">Discord\u2019s content delivery network<\/a> (CDN) for hosting and delivery. It was the target of a major takedown operation by Europol in May 2025, which was conducted in partnership with other industry experts.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6.5\">\n<figure class=\"image-figure\" readability=\"3\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/25\/f\/interpol-operation-secure\/interpol-opsecure-fig3.png\" alt=\"Figure 3. The observed infection chain of how Lumma Stealer used fake GithHub repositories\u202ffor deployment \"> <\/p>\n<p><figcaption>Figure 3. The observed infection chain of how Lumma Stealer used fake GithHub repositories\u202ffor deployment <\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"34.734501347709\">\n<div readability=\"15.654986522911\">\n<p><b>Rhadamanthys<\/b><\/p>\n<p>First observed in late 2022, Rhadamanthys is a sophisticated infostealer distributed through <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/e\/unmasking-fake-captcha-cases.html\">phishing<\/a>, fake installers, and pirated software. It collects credentials, cookies, and detailed system information, communicating over encrypted channels to exfiltrate stolen data. Its reliability and customization options make it a favorite among threat actors.\u202f<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\" readability=\"6\">\n<figure class=\"image-figure\" readability=\"2\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/25\/f\/interpol-operation-secure\/interpol-opsecure-fig4.png\" alt=\"Figure 4. Infection Chain of Fake CAPTCHA campaign distributing infostealers.\u202f\"> <\/p>\n<p><figcaption>Figure 4. Infection Chain of Fake CAPTCHA campaign distributing infostealers.\u202f<\/figcaption><\/p>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"41.957654723127\">\n<div readability=\"31.468241042345\">\n<p><span class=\"body-subhead-title\">Continuing the Global Fight Against Cybercrime\u202f<\/span><\/p>\n<p>Trend\u2019s participation in Operation Secure underscores our steadfast commitment to public-private collaboration in the fight against global cybercrime.&nbsp;<\/p>\n<p>We have previously partnered with INTERPOL in its <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/b\/trend-micro-and-interpol-join-forces-again-for-operation-synergi.html\">Operation Synergia<\/a> that took down over 1,300 C&amp;C servers which led to 30 house searches and the identification of 70 suspects facilitating phishing, banking malware, and ransomware activity.&nbsp;<\/p>\n<p>Trend also contributed to INTERPOL\u2019s operation to help Brazilian and Spanish law enforcement agencies analyze Grandoreiro malware samples as part of their national cybercrime investigations that\u202fresulted in the arrest of five administrators behind a <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/d\/trend-micro-collaborated-with-interpol-in-cracking-down-grandore.html\">Grandoreiro operation<\/a>.&nbsp;<\/p>\n<p>Trend also partnered with INTERPOL in <a href=\"https:\/\/www.interpol.int\/en\/News-and-Events\/News\/2025\/More-than-300-arrests-as-African-countries-clamp-down-on-cyber-threats\" target=\"_blank\">Operation Red Card<\/a>&nbsp;by providing intelligence that helped lead to the arrest of 306 suspects and the seizure of 1,842 devices involved in banking, investment, and messaging app scams.&nbsp;&nbsp;<\/p>\n<p>As cybercriminals continuously evolve their tactics, proactive intelligence sharing and cross-border coordination remain essential for effective defence.\u202fOur partnership with INTERPOL endures as Trend persists in its commitment to securing our increasingly connected world.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/f\/interpol-operation-secure.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this blog, we discuss how Trend Micro played a pivotal role in Operation Secure, a multi-national law enforcement effort that dismantled the infrastructure behind widespread infostealer malware campaigns across Asia and the Pacific. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9521,9534],"class_list":["post-58799","post","type-post","status-publish","format-standard","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-crime","tag-trend-micro-research-latest-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Operation Secure: Trend Micro&#039;s Threat Intelligence Fuels INTERPOL&#039;s Infostealer Infrastructure Takedown\u202f 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Operation Secure: Trend Micro&#039;s Threat Intelligence Fuels INTERPOL&#039;s Infostealer Infrastructure Takedown\u202f 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-11T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/interpol-opsecure-thumbresized:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Operation Secure: Trend Micro&#8217;s Threat Intelligence Fuels INTERPOL&#8217;s Infostealer Infrastructure Takedown\u202f\",\"datePublished\":\"2025-06-11T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/\"},\"wordCount\":1033,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/interpol-opsecure-thumbresized:Large?qlt=80\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Crime\",\"Trend Micro Research : Latest News\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/\",\"name\":\"Operation Secure: Trend Micro's Threat Intelligence Fuels INTERPOL's Infostealer Infrastructure Takedown\u202f 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/interpol-opsecure-thumbresized:Large?qlt=80\",\"datePublished\":\"2025-06-11T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/interpol-opsecure-thumbresized:Large?qlt=80\",\"contentUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/interpol-opsecure-thumbresized:Large?qlt=80\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Operation Secure: Trend Micro&#8217;s Threat Intelligence Fuels INTERPOL&#8217;s Infostealer Infrastructure Takedown\u202f\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Operation Secure: Trend Micro's Threat Intelligence Fuels INTERPOL's Infostealer Infrastructure Takedown\u202f 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/","og_locale":"en_US","og_type":"article","og_title":"Operation Secure: Trend Micro's Threat Intelligence Fuels INTERPOL's Infostealer Infrastructure Takedown\u202f 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-06-11T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/interpol-opsecure-thumbresized:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Operation Secure: Trend Micro&#8217;s Threat Intelligence Fuels INTERPOL&#8217;s Infostealer Infrastructure Takedown\u202f","datePublished":"2025-06-11T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/"},"wordCount":1033,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/interpol-opsecure-thumbresized:Large?qlt=80","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Crime","Trend Micro Research : Latest News"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/","url":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/","name":"Operation Secure: Trend Micro's Threat Intelligence Fuels INTERPOL's Infostealer Infrastructure Takedown\u202f 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/interpol-opsecure-thumbresized:Large?qlt=80","datePublished":"2025-06-11T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/#primaryimage","url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/interpol-opsecure-thumbresized:Large?qlt=80","contentUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/interpol-opsecure-thumbresized:Large?qlt=80"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/operation-secure-trend-micros-threat-intelligence-fuels-interpols-infostealer-infrastructure-takedown\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Operation Secure: Trend Micro&#8217;s Threat Intelligence Fuels INTERPOL&#8217;s Infostealer Infrastructure Takedown\u202f"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58799","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58799"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58799\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}