# Law Enforcement Delivers Major Blow to Amadey and StealC Malware Operations in Coordinated International Takedown
Microsoft, Europol, and law enforcement agencies from six nations have successfully disrupted the infrastructure powering two of the most prolific malware families fueling the global cybercrime ecosystem. Operation Endgame, a coordinated international effort announced June 24, 2026, seized or took offline 326 servers and 142 domains used by the Amadey and StealC malware families, effectively crippling operations that have compromised hundreds of thousands of devices worldwide.
The action represents a watershed moment in law enforcement's approach to tackling cybercriminal infrastructure—targeting the foundational tools and services that enable everything from credential theft to ransomware deployment.
## The Threat: Two Complementary Malware Families
Amadey and StealC operate as a dangerous pair within the modern cybercriminal toolkit, each filling a distinct but mutually reinforcing role:
### Amadey — The Initial Foothold
### StealC — The Information Harvester
- Username and password combinations
- Cryptocurrency wallets
- Banking credentials
- Session tokens and API keys
## Background and Context: The Scale of the Problem
Before disruption, these malware families had become endemic across the threat landscape. According to Microsoft's investigation, Amadey and StealC alone were linked to more than 140,000 infected devices during just the first two weeks of May 2026—a staggering figure that underscores how widely distributed these tools have become.
The operation seized an opportunity presented by law enforcement's evolving approach: rather than chasing individual threat actors, agencies are now targeting the infrastructure and services that enable mass-scale cybercrime. This represents a strategic shift from prosecution of individual actors to dismantling the criminal-as-a-service ecosystem.
### The International Coalition
Operation Endgame demonstrates unprecedented coordination:
| Component | Details |
|-----------|---------|
| Law Enforcement Agencies | Canada, Denmark, Germany, the Netherlands, United Kingdom, United States |
| Coordination Bodies | Europol, Eurojust |
| Private-Sector Partners | Microsoft, ESET, Proofpoint, IBM X-Force, Bitsight, Infoblox, Orange Cyberdefense, Shadowserver, Have I Been Pwned, Spamhaus |
| Scope of Disruption | 326 servers, 142 domains |
| Associated Cryptocurrency | €41 million ($47 million) identified |
| Credentials Recovered | Approximately 27 million stolen credentials from over 385,000 compromised systems |
## Technical Details: How Law Enforcement Executed the Disruption
The operation employed multiple technical and legal mechanisms to neutralize the malware infrastructure:
### Identification and Intelligence Gathering
### Takedown Methods
### Additional Target: SocGholish/FakeUpdates
The operation also disrupted SocGholish (also known as FakeUpdates), a malware loader that spreads through compromised websites serving fraudulent browser update prompts—a particularly effective infection vector targeting unsuspecting users.
## Implications for Organizations and Industries
### The Credential Marketplace Crisis
The recovery of 27 million stolen credentials represents only the credentials law enforcement could identify and recover—a fraction of the total harvested through these operations. The credential underground economy poses a cascading risk:
1. Stolen credentials are resold multiple times through initial-access brokers and underground forums
2. Each credential can enable multiple attack chains: lateral movement, data theft, ransomware deployment, financial fraud
3. Time-lag exploitation: Credentials stolen weeks or months ago may still provide active access to networks
### Organizational Exposure
Organizations should assume that any systems compromised during the Amadey/StealC operation may have been:
### The Ransomware Supply Chain
This operation disrupts a critical link in the ransomware value chain:
## Recommendations for Defenders
### Immediate Actions (Within 48 Hours)
### Short-Term Measures (Within 2 Weeks)
### Long-Term Defensive Posture
---
## HackWire Analysis
Operation Endgame signals a critical inflection point in how law enforcement combats cybercrime: infrastructure disruption works, and it works fast. While individual threat actor prosecutions take years, dismantling the service platforms they depend on can be executed in coordinated strikes that multiply impact across an entire ecosystem.
The €41 million in identified cryptocurrency and 27 million recovered credentials represent tangible damage to criminal operations, but the real significance lies in operational friction. Amadey and StealC operators must now rebuild C2 infrastructure, migrate their affiliate networks, establish new payment mechanisms, and regain trust from customers in a market that just witnessed their tools seized. That friction is expensive, time-consuming, and uncertain—exactly the conditions that reduce lower-tier cybercriminal activity while driving up costs for sophisticated operators.
However, defenders should not interpret this as a permanent defeat of credential theft. The 27 million credentials recovered are almost certainly a subset of total credentials stolen—many may already be in underground circulation, and criminal groups typically maintain operational backups. The true measure of this operation's success will not be evident for 6-12 months, when we can assess whether credential-based initial access attacks have genuinely decreased or simply shifted to alternative stealer malware families.
The private-sector participation—particularly Microsoft, ESET, and Proofpoint—demonstrates that cybersecurity vendors now function as quasi-law-enforcement infrastructure. Organizations should recognize that their own security tools are contributing to intelligence gathering that shapes global enforcement operations. This is a positive development for collective defense, but it also means that reporting suspicious activity to your security vendor is increasingly an act of public health, not just private protection.
For defenders, the immediate lesson is stark: stolen credentials are now evidence of police action. If your credentials appear in breach notification services, assume they've been weaponized and prioritize remediation accordingly. The second lesson: infrastructure matters more than individual actors. Law enforcement's new focus on takedowns rather than arrests should encourage organizations to invest in architectural resilience and credential hygiene that doesn't depend on attackers being arrested—because credential-based attacks will persist regardless.
— HackWire Editorial
---
## Related Coverage