Court, Explained
U.S. Federal District Courts
←Back to docket
S.D.N.Y.Substantive rulingFiled July 1, 2025

Google LLC v. Does 1-25

Judge
James Oetken
Docket
1:25-cv-04503
Court
U.S. District Court · Southern District of New York
Pages
12
Preliminary InjunctionCivil Procedure
In one sentence

In Google v. Does 1–25, Judge Oetken issued a worldwide preliminary injunction against an alleged botnet operation accused of malware, fraud, and cybercrime.

Who this affects

The Doe defendants and anyone acting with them who receives notice are barred worldwide from operating or facilitating the BadBox 2.0 botnet and related activities. Hosting providers, service providers, and domain registries connected to identified domains may be required to block traffic, disable services, preserve information, and assist Google. Google and its customers receive the protections described in the injunction.

What happened

Google LLC sued Does 1–25, calling them the BadBox 2.0 Enterprise, and alleged that they operated a botnet infecting more than ten million devices. Google brought claims under the Computer Fraud and Abuse Act and the Racketeer Influenced and Corrupt Organizations Act.

The court found that Google had shown immediate, irreparable harm, a likelihood of success on its claims, hardships favoring Google, and a public interest in stopping the alleged conduct. The court also found that it had jurisdiction and that the case was properly filed in the Southern District of New York.

The court issued a worldwide preliminary injunction barring the defendants and others with notice from operating the botnet, distributing malicious code, accessing protected computers without authorization, selling proxy services, committing advertising fraud, and related conduct. Judge Oetken also authorized alternative service, directed domain-related providers and registries to help disable or transfer identified domains, and found that Google’s $75,000 bond satisfied the bond requirement with no additional bond needed.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Google LLC v. Does 1-25 · No. 1:25-cv-04503
Judge
James Oetken
Date
July 1, 2025

Background

Google LLC sued Does 1–25, whom Google identified as the “BadBox 2.0 Enterprise.” Google alleged that the defendants controlled and operated a botnet— a network of compromised devices—containing more than ten million devices. According to the complaint and the court’s findings, the defendants distributed malware, infected devices using the Android Open Source Project operating system, used infected devices for advertising fraud, sold access to the devices as residential proxies, and facilitated other criminal activity.

Google asserted claims under the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, and the Racketeer Influenced and Corrupt Organizations Act (RICO), 18 U.S.C. § 1962(c)–(d). Google moved for emergency relief under Federal Rule of Civil Procedure 65 and the All Writs Act. The court had previously issued and extended a temporary restraining order.

Court’s Findings

The court found federal-question jurisdiction over Google’s CFAA and RICO claims. It found personal jurisdiction because the defendants allegedly distributed malware, infected devices, sent commands to infected computers, and caused harm in New York. It also found venue proper in the Southern District of New York.

The court concluded that Google’s complaint stated claims under the CFAA and RICO. For the CFAA claims, the court found that Google was likely to prove that the defendants knowingly transmitted malicious code and commands to protected computers, intentionally caused unauthorized damage, and accessed protected computers without authorization to further fraud and obtain something of value. The court found that the defendants’ conduct caused Google losses exceeding $5,000 in one year.

For the RICO claims, the court found that Google was likely to prove that the defendants operated an enterprise with a shared purpose, worked together through different groups and infrastructure, and engaged in a pattern of racketeering activity. The court identified alleged CFAA violations and wire fraud as predicate acts and found that Google suffered injury to its business or property through advertising fraud, refunds for fraudulent traffic, and expenditures to investigate and combat the alleged schemes.

Preliminary Injunction

The court found all required preliminary-injunction factors satisfied: irreparable harm, a likelihood of success on the merits or a substantial question about the merits, a balance of hardships favoring Google, and a public interest in the injunction. It found that the botnet threatened internet and device security, harmed Google’s reputation and goodwill, caused economic losses, and could be used for additional attacks. The court also found that continued malware distribution and related criminal schemes would harm consumers and the public.

The court preliminarily restrained and enjoined the defendants, their agents and representatives, and others acting with them who received actual notice of the order. The order applies worldwide and prohibits, among other things, unauthorized access to Google customers’ protected computers; sending malicious code; operating or facilitating the BadBox 2.0 botnet; stealing information; delivering code for proxy access or advertising fraud; selling proxy services; committing advertising fraud; accessing or controlling identified domains; and similar harmful activity.

The order also allows Google to serve the order through email, website publication, and other online methods because the court found traditional service would be futile. Google may serve the order on hosting companies, service providers, and domain registries and request actions including blocking traffic, disabling or suspending services, preserving records, identifying the defendants, and preventing circumvention. Domain registries must take specified steps to change registrar control, prevent transfers or deletion, and work with Google to secure the domains. Google may seek permission to add domains or Internet addresses to the complaint’s appendix.

Bond and Disposition

The court ruled that Google’s submission of a $75,000 bond satisfied the bond requirement from the temporary restraining order and that no additional bond was necessary. The resulting preliminary injunction remains the order described above, including its provisions concerning the defendants, identified domains, and entities that receive notice.

The authoritative version

Read the full 12-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.