Belarusian authorities reported arresting an unnamed man in connection with the Andromeda botnet in November 2017. The operation disrupted the botnet’s infrastructure, but the public record reviewed here does not establish that the suspect was its “mastermind,” confirm his identity, or document a later conviction.
What happened in the Andromeda operation?
The coordinated operation took place on 29 November 2017; Europol announced it on 4 December. The FBI and German investigators worked with Europol’s European Cybercrime Centre (EC3), the Joint Cybercrime Action Task Force, Eurojust and private-sector partners. Investigators targeted Andromeda’s infrastructure, including by sinkholing domains: redirecting traffic from the botnet’s command-and-control system to infrastructure controlled for monitoring and disruption. Europol reported that a suspect was arrested in Belarus. Europol’s announcement describes the operation.
The infrastructure disruption and the arrest were related parts of the operation, but they were not the same result: sinkholing interfered with the botnet’s communications, while the arrest concerned one alleged participant. Microsoft’s case study describes partners redirecting traffic to sinkholes, collecting forensic evidence and coordinating with national computer emergency response teams (CERTs) to help remove the malware from infected devices.
Who was arrested, and was he identified as “Ar3s”?
The reviewed public reports do not give the suspect’s legal name. Reuters reported that Belarus’s Ministry of Internal Affairs described him as born in 1983 and living in the Gomel region. Belarus’s Investigative Committee, according to Interfax, alleged that he sold malicious software, administered cybercrime forums, helped with purchases and updates, and provided technical support. Those are allegations and agency statements, not findings established by a court.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Reuters reported that Recorded Future assessed the suspect was likely the hacker using the handle “Ar3s.” Reuters said it could not confirm that identity, and Belarusian authorities declined to name the man. The alias therefore remains an attributed, unconfirmed identification—not a publicly verified identity. Reuters’ report covers the arrest and attribution; Interfax’s report relays the investigators’ allegations.
What was Andromeda, also called Gamarue?
Andromeda, also known as Gamarue, was not a single isolated infection. Microsoft described it as a modular crime kit and malware that built a network of infected devices and distributed other malware. Microsoft’s 2018 case study says it was active from 2011 to 2017 and associates it with 80 malware families.
Microsoft’s case-study key facts provide a sense of the operation’s reported scale. These are figures published by Microsoft in 2018, not independently verified counts or measures of current infections:
| Figure | What Microsoft reported |
|---|---|
| 230 countries | Countries affected |
| 23 million | Infected IP addresses |
| 17 million per month | Infected machines at peak |
| 44,000 | Malware samples identified |
| 464 | Distinct botnets |
| 80 | Malware families associated with Andromeda |
| 1,214 | Command-and-control centers taken down |
Microsoft characterized the malware as active and proliferating for seven years. That duration is consistent with the case study’s 2011–2017 activity period; it should not be read as evidence that Andromeda remains active today.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →What did the operation’s early figures show?
Reuters reported that Europol said more than 2 million unique internet addresses sent information to the sinkhole during the first 48 hours after the operation began on 29 November 2017. Reuters also relayed Europol’s statement that more than 55 percent of computers found infected in an earlier operation a year before were still infected. Both figures describe historical observations reported at the time; neither is a current infection estimate.
What did Belarusian investigators allege about sales?
Interfax reported investigators’ allegation that the suspect received $500 for each malware sale and $10 for each update. At the time, investigators were still examining the number of alleged episodes and the income involved. These amounts were reported allegations, not adjudicated prices or a proven total of proceeds.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Was the suspect convicted, and is Andromeda active now?
The sources cited here do not establish a later conviction, sentence or other case disposition. They also do not establish present-day Andromeda activity or a current remediation action for people whose devices may have been affected in the past. The historical operation is evidence of a 2017 disruption, not a current threat assessment.
Steven Wilson, then head of Europol’s European Cybercrime Centre, called the operation “another great example of international law enforcement working together with industry partners to tackle the most significant cybercriminals.” That was his characterization of the cooperation, not a legal finding about the arrested suspect. Microsoft’s case study attributes the statement to Wilson.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

