On 28 October 2024 the Dutch National Police, working with the FBI, Eurojust and partners in the United Kingdom, Australia, Belgium and Portugal, announced Operation Magnus: the disruption of RedLine and META, two of the most widely rented information-stealing malware platforms in operation.
An infostealer is not ransomware. It does not announce itself. It runs once on a machine, empties the browser of saved passwords, session cookies and card details, sends them to a collection point and leaves. The victim usually never learns it happened.
What Makes This Takedown Different
Most disruptions seize servers. Reporting on Magnus describes law enforcement obtaining the source code, the REST API services, the licence servers, the stealer binaries and the Telegram bots — and, critically, the IP addresses, credentials and registration details of the customers.
These are malware-as-a-service products. The operators write and host; thousands of separate criminals rent. Seizing the licence server means seizing the customer database, which turns one takedown into a lead list — a materially different outcome from taking a botnet offline and watching it rebuild.
The Credential Figure Needs Its Label
Reporting has put the combined haul at over 451 million unique credentials, including cookies usable to bypass multi-factor authentication. That figure comes from the investigation and from vendor analysis of the seized material, not from an audited count, and this desk grades the file medium accordingly.
The cookie detail is the part that matters more than the number. A stolen password is defeated by a second factor. A stolen session cookie is the second factor already satisfied — it is proof that the check was passed, and replaying it skips the check entirely.
This is the closest thing the corpus has to a file on session hijacking, and it arrives sideways: not as an intrusion into one organisation, but as an industrial supply of pre-authenticated sessions sold by subscription.
Where The Victims Are In This
Nowhere, mostly. The people whose credentials sat in those databases were infected individually, months or years apart, usually through a cracked download or a malicious advertisement. There is no breached organisation to notify them, no regulator with jurisdiction over their laptop, and no incident number.
The corpus filed at 24-0413 that notification depends on an entity that still exists and can afford to write. Here there was never an entity at all. What the takedown produced instead was a check-your-exposure service — which is a real service, and which asks the affected person to come looking.
Compiled from law-enforcement announcements of Operation Magnus and contemporaneous reporting of them, listed below. The 451 million credential figure originates with the investigation and with vendor analysis of seized material; it is a count of records, not of distinct people, and is labelled as reported rather than established. The description of what was seized follows the announcements. This desk has not reviewed the seized material and makes no assessment of it. The account of how infostealers and session cookies work is general technique. Graded medium. Corrections: corrections@forensicpost.com.