# Massive Takedown: 27 Million Stolen Credentials Recovered in Coordinated Strike Against Amadey and StealC Malware Networks


A landmark international law enforcement operation has dismantled the infrastructure behind two of the cybercriminal ecosystem's most prolific malware-as-a-service offerings, disrupting what authorities describe as the "assembly lines" that power ransomware operations, financial fraud, and attacks on critical infrastructure.


## The Operation: Scale and Coordination


Law enforcement agencies from the Netherlands, Canada, Germany, and the United States partnered with leading private sector security firms—including Bitdefender, Bitsight, ESET, and Microsoft—to execute a two-week takedown operation that has effectively crippled the Amadey and StealC malware networks.


The results are substantial:


| Metric | Recovery |

|--------|----------|

| Stolen Credentials | 27 million recovered |

| Cryptocurrency Assets | $47 million identified and restricted |

| Servers Dismantled | 326 |

| Malicious Domains | 142 |

| WordPress Sites Cleaned | 15,000 (related SocGholish operation) |


"The main common goal was to disrupt the 'assembly lines' cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure," Europol stated in an official announcement.


This takedown arrives on the heels of a separate but coordinated operation targeting SocGholish, another loader malware family implicated in distributing secondary payloads across compromised WordPress installations. Together, these actions represent a rare display of synchronized international pressure against organized cybercrime infrastructure.


## Amadey: The Modular Loader with Global Reach


Amadey is a C++-based modular backdoor that has operated continuously since October 2018 under the threat actor alias "InCrease." Marketed as a malware-as-a-service offering, Amadey is priced at $600 for a single license, with additional fees of $50 charged per rebuild—a pricing model that has enabled its widespread adoption among mid-tier threat actors.


### Capabilities and Command Set


Amadey's functionality is extensive, with the latest version (5.87) supporting:


  • Reconnaissance: Machine fingerprinting and system enumeration
  • File Operations: Download DLLs, MSI installers, and PowerShell scripts
  • Command Execution: Direct shell access via cmd.exe
  • Exfiltration: Screenshot capture and clipboard monitoring
  • Persistence & Access: Enable RDP, establish SOCKS proxies, deploy reverse shells or VNC sessions
  • Lateral Movement: Credential harvesting for network propagation

  • ### Growth Trajectory


    Amadey's prevalence has grown dramatically. According to data published by Mitsui Bussan Secure Directions, the daily count of active command-and-control (C2) servers remained modest until 2022, fluctuating between 2 and 18 daily active servers. Beginning in January 2023, however, activity surged to between 5 and 30 active servers daily—a clear indicator of widespread adoption.


    The volume of payloads distributed through Amadey tells an even more dramatic story:


  • 2019: 66 samples
  • 2020: 260 samples
  • 2021: 1,231 samples
  • 2022: 3,500 samples
  • 2023: 8,360 samples
  • 2024: 7,619 samples
  • 2025: 11,635 samples (peak)
  • YTD 2026: 1,837 samples

  • This near-exponential growth illustrates how malware-as-a-service offerings have democratized access to dangerous tooling, allowing even less sophisticated threat actors to deploy credible, feature-rich attacks.


    ## StealC: The Information Stealer Engine


    StealC represents a different category of malware—an aggressive information stealer rather than a loader. First observed in January 2023, StealC was marketed by a threat actor using the handle "plymouth" at a price point of $300 per month (or $1,000 for six months).


    ### Data Extraction Scope


    StealC is engineered to exfiltrate a comprehensive range of sensitive data:


  • Credentials and login information
  • Session Cookies for account hijacking
  • Autofill Data from browsers
  • Credit Card Information
  • Browsing History
  • Browser Extension Data
  • Screenshots of user activity

  • ### Distribution Channels


    Unlike Amadey, which relies primarily on phishing and other malware loaders for initial distribution, StealC employs a more diversified approach:


  • ClickFix Lures: Fake technical support messages
  • Malware Loader Chains: Distribution via Amadey itself and other loaders
  • Multi-Stage Campaigns: Coordination with other malware families

  • ## The "Assembly Line" Model


    What law enforcement and security firms characterize as an "assembly line" is a sophisticated division of labor within the criminal ecosystem:


    1. Initial Access: Loaders like Amadey or SocGholish compromise systems via phishing or watering hole attacks

    2. Secondary Payload Delivery: These loaders inject information stealers like StealC to harvest credentials and data

    3. Monetization: Stolen data is sold or leveraged for follow-up attacks

    4. Escalation: Financial malware, ransomware payloads, or APT tools are deployed for high-value targets


    This pipeline has become increasingly efficient and automated—a point underscored by the 27 million stolen credentials recovered in this operation, many of which were likely staged for use in downstream attacks.


    ## Implications for Organizations


    The takedown of Amadey and StealC infrastructure disrupts but does not eliminate the broader malware-as-a-service ecosystem. Organizations face several critical imperatives:


    ### Immediate Actions


  • Credential Compromise Alerts: Monitor breach notification databases (including this recovered dataset) for employee or customer credentials
  • Multi-Factor Authentication: Enforce MFA across all critical systems, particularly email and administrative tools
  • Browser Security: Deploy endpoint detection and response (EDR) solutions capable of monitoring browser-based data exfiltration

  • ### Long-Term Resilience


  • Email Security: Implement robust anti-phishing controls, including URL rewriting and attachment sandboxing
  • Endpoint Hardening: Disable unnecessary scripting engines and enforce application allowlisting where feasible
  • WordPress Security: For organizations operating WordPress installations, apply patches immediately and conduct security audits of plugins and themes
  • Credential Inventory: Conduct a comprehensive audit of stored credentials; migrate from plaintext storage to a secrets management solution

  • ## Recommendations for Defenders


    For Security Teams:

  • Cross-reference the recovered 27 million credentials against employee and customer databases
  • Update SIEM rules to detect C2 communications associated with known Amadey and StealC infrastructure
  • Review logs for indicators of compromise (IoCs) provided by Europol and participating agencies

  • For System Administrators:

  • Patch WordPress installations immediately
  • Review web server logs for evidence of malware downloads or unusual PowerShell execution
  • Monitor for suspicious RDP enablement or unexpected SOCKS proxy traffic

  • For CISOs:

  • Report findings to the board; the scale of this operation underscores systemic risk to credential security
  • Reassess the organization's information security budgets in light of the breadth of capabilities demonstrated by Amadey and StealC

  • ---


    ## HackWire Analysis


    This takedown is significant not because it eliminates cybercriminal malware—it doesn't—but because it exposes the factory-like efficiency of modern cybercrime infrastructure. The recovery of 27 million credentials is sobering, but the real story is the *distribution model* these criminals perfected.


    For years, the security industry has treated Amadey and StealC as isolated malware families. But this operation reveals what Europol rightly calls them: components in an assembly line. The threat actors succeeded not by building the most sophisticated tools, but by building the most *operationally efficient* ecosystem. A $600 license to Amadey, a $300/month subscription to StealC, integration with commodity phishing infrastructure—and suddenly, mid-tier criminals can operate at enterprise scale.


    The takedown's international coordination is also noteworthy. Unlike past operations that targeted individual campaigns or families, this one systematically dismantled shared infrastructure: 326 servers, 142 domains. That's infrastructure destruction, not just evidence collection.


    But here's what defenders need to internalize: the assembly line model is not going away. Amarey and StealC will be replaced by functionally identical services under different names within weeks. The real vulnerability isn't the malware—it's the human element. Phishing still works. Credential reuse still works. Unpatched WordPress sites still get compromised.


    This operation is a reminder that while law enforcement can disrupt criminal infrastructure, the burden of defense still rests with organizations. Update your patches. Enforce MFA. Stop reusing credentials. The criminals behind Amadey and StealC already have 27 million reasons to build the next assembly line.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)