# Massive Takedown: 27 Million Stolen Credentials Recovered in Coordinated Strike Against Amadey and StealC Malware Networks
A landmark international law enforcement operation has dismantled the infrastructure behind two of the cybercriminal ecosystem's most prolific malware-as-a-service offerings, disrupting what authorities describe as the "assembly lines" that power ransomware operations, financial fraud, and attacks on critical infrastructure.
## The Operation: Scale and Coordination
Law enforcement agencies from the Netherlands, Canada, Germany, and the United States partnered with leading private sector security firms—including Bitdefender, Bitsight, ESET, and Microsoft—to execute a two-week takedown operation that has effectively crippled the Amadey and StealC malware networks.
The results are substantial:
| Metric | Recovery |
|--------|----------|
| Stolen Credentials | 27 million recovered |
| Cryptocurrency Assets | $47 million identified and restricted |
| Servers Dismantled | 326 |
| Malicious Domains | 142 |
| WordPress Sites Cleaned | 15,000 (related SocGholish operation) |
"The main common goal was to disrupt the 'assembly lines' cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure," Europol stated in an official announcement.
This takedown arrives on the heels of a separate but coordinated operation targeting SocGholish, another loader malware family implicated in distributing secondary payloads across compromised WordPress installations. Together, these actions represent a rare display of synchronized international pressure against organized cybercrime infrastructure.
## Amadey: The Modular Loader with Global Reach
Amadey is a C++-based modular backdoor that has operated continuously since October 2018 under the threat actor alias "InCrease." Marketed as a malware-as-a-service offering, Amadey is priced at $600 for a single license, with additional fees of $50 charged per rebuild—a pricing model that has enabled its widespread adoption among mid-tier threat actors.
### Capabilities and Command Set
Amadey's functionality is extensive, with the latest version (5.87) supporting:
### Growth Trajectory
Amadey's prevalence has grown dramatically. According to data published by Mitsui Bussan Secure Directions, the daily count of active command-and-control (C2) servers remained modest until 2022, fluctuating between 2 and 18 daily active servers. Beginning in January 2023, however, activity surged to between 5 and 30 active servers daily—a clear indicator of widespread adoption.
The volume of payloads distributed through Amadey tells an even more dramatic story:
This near-exponential growth illustrates how malware-as-a-service offerings have democratized access to dangerous tooling, allowing even less sophisticated threat actors to deploy credible, feature-rich attacks.
## StealC: The Information Stealer Engine
StealC represents a different category of malware—an aggressive information stealer rather than a loader. First observed in January 2023, StealC was marketed by a threat actor using the handle "plymouth" at a price point of $300 per month (or $1,000 for six months).
### Data Extraction Scope
StealC is engineered to exfiltrate a comprehensive range of sensitive data:
### Distribution Channels
Unlike Amadey, which relies primarily on phishing and other malware loaders for initial distribution, StealC employs a more diversified approach:
## The "Assembly Line" Model
What law enforcement and security firms characterize as an "assembly line" is a sophisticated division of labor within the criminal ecosystem:
1. Initial Access: Loaders like Amadey or SocGholish compromise systems via phishing or watering hole attacks
2. Secondary Payload Delivery: These loaders inject information stealers like StealC to harvest credentials and data
3. Monetization: Stolen data is sold or leveraged for follow-up attacks
4. Escalation: Financial malware, ransomware payloads, or APT tools are deployed for high-value targets
This pipeline has become increasingly efficient and automated—a point underscored by the 27 million stolen credentials recovered in this operation, many of which were likely staged for use in downstream attacks.
## Implications for Organizations
The takedown of Amadey and StealC infrastructure disrupts but does not eliminate the broader malware-as-a-service ecosystem. Organizations face several critical imperatives:
### Immediate Actions
### Long-Term Resilience
## Recommendations for Defenders
For Security Teams:
For System Administrators:
For CISOs:
---
## HackWire Analysis
This takedown is significant not because it eliminates cybercriminal malware—it doesn't—but because it exposes the factory-like efficiency of modern cybercrime infrastructure. The recovery of 27 million credentials is sobering, but the real story is the *distribution model* these criminals perfected.
For years, the security industry has treated Amadey and StealC as isolated malware families. But this operation reveals what Europol rightly calls them: components in an assembly line. The threat actors succeeded not by building the most sophisticated tools, but by building the most *operationally efficient* ecosystem. A $600 license to Amadey, a $300/month subscription to StealC, integration with commodity phishing infrastructure—and suddenly, mid-tier criminals can operate at enterprise scale.
The takedown's international coordination is also noteworthy. Unlike past operations that targeted individual campaigns or families, this one systematically dismantled shared infrastructure: 326 servers, 142 domains. That's infrastructure destruction, not just evidence collection.
But here's what defenders need to internalize: the assembly line model is not going away. Amarey and StealC will be replaced by functionally identical services under different names within weeks. The real vulnerability isn't the malware—it's the human element. Phishing still works. Credential reuse still works. Unpatched WordPress sites still get compromised.
This operation is a reminder that while law enforcement can disrupt criminal infrastructure, the burden of defense still rests with organizations. Update your patches. Enforce MFA. Stop reusing credentials. The criminals behind Amadey and StealC already have 27 million reasons to build the next assembly line.
— *HackWire Editorial*
---
## Related Coverage