# Law Enforcement Delivers Major Blow to Amadey and StealC Malware Operations in Coordinated International Takedown


Microsoft, Europol, and law enforcement agencies from six nations have successfully disrupted the infrastructure powering two of the most prolific malware families fueling the global cybercrime ecosystem. Operation Endgame, a coordinated international effort announced June 24, 2026, seized or took offline 326 servers and 142 domains used by the Amadey and StealC malware families, effectively crippling operations that have compromised hundreds of thousands of devices worldwide.


The action represents a watershed moment in law enforcement's approach to tackling cybercriminal infrastructure—targeting the foundational tools and services that enable everything from credential theft to ransomware deployment.


## The Threat: Two Complementary Malware Families


Amadey and StealC operate as a dangerous pair within the modern cybercriminal toolkit, each filling a distinct but mutually reinforcing role:


### Amadey — The Initial Foothold

  • Operates as a botnet and malware loader designed to establish initial access to victim systems
  • Sold through malware-as-a-service (MaaS) platforms where affiliates pay for access to builders, management panels, and hosting
  • Commonly deployed by ransomware gangs seeking network entry points
  • Also used by state-sponsored hacking groups for targeted network breaches
  • Creates an infection channel for secondary payloads including additional malware and ransomware

  • ### StealC — The Information Harvester

  • A credential-stealing trojan that extracts sensitive authentication data from infected machines
  • Targets:
  • - Username and password combinations

    - Cryptocurrency wallets

    - Banking credentials

    - Session tokens and API keys

  • Widely leveraged in ClickFix attacks, including fake instructional videos on TikTok and deceptive FileFix malware campaigns
  • Stolen credentials are monetized through underground marketplaces and sold to initial-access brokers (IABs), who then resell them to ransomware operators

  • ## Background and Context: The Scale of the Problem


    Before disruption, these malware families had become endemic across the threat landscape. According to Microsoft's investigation, Amadey and StealC alone were linked to more than 140,000 infected devices during just the first two weeks of May 2026—a staggering figure that underscores how widely distributed these tools have become.


    The operation seized an opportunity presented by law enforcement's evolving approach: rather than chasing individual threat actors, agencies are now targeting the infrastructure and services that enable mass-scale cybercrime. This represents a strategic shift from prosecution of individual actors to dismantling the criminal-as-a-service ecosystem.


    ### The International Coalition


    Operation Endgame demonstrates unprecedented coordination:


    | Component | Details |

    |-----------|---------|

    | Law Enforcement Agencies | Canada, Denmark, Germany, the Netherlands, United Kingdom, United States |

    | Coordination Bodies | Europol, Eurojust |

    | Private-Sector Partners | Microsoft, ESET, Proofpoint, IBM X-Force, Bitsight, Infoblox, Orange Cyberdefense, Shadowserver, Have I Been Pwned, Spamhaus |

    | Scope of Disruption | 326 servers, 142 domains |

    | Associated Cryptocurrency | €41 million ($47 million) identified |

    | Credentials Recovered | Approximately 27 million stolen credentials from over 385,000 compromised systems |


    ## Technical Details: How Law Enforcement Executed the Disruption


    The operation employed multiple technical and legal mechanisms to neutralize the malware infrastructure:


    ### Identification and Intelligence Gathering

  • Microsoft's Digital Crimes Unit identified over 200 malicious command-and-control (C2) domains and IP addresses
  • ESET disrupted approximately 50 domains and nearly 200 active C2 servers
  • Bitsight provided infrastructure mapping and analysis
  • Proofpoint and IBM X-Force contributed malware analysis and threat intelligence

  • ### Takedown Methods

  • Court-ordered seizures and domain takedowns
  • Domain registrar notifications and cancellations
  • Internet service provider interventions
  • DNS sinkholing of malicious domains
  • Infrastructure provider cooperation to remove hosting services

  • ### Additional Target: SocGholish/FakeUpdates

    The operation also disrupted SocGholish (also known as FakeUpdates), a malware loader that spreads through compromised websites serving fraudulent browser update prompts—a particularly effective infection vector targeting unsuspecting users.


    ## Implications for Organizations and Industries


    ### The Credential Marketplace Crisis


    The recovery of 27 million stolen credentials represents only the credentials law enforcement could identify and recover—a fraction of the total harvested through these operations. The credential underground economy poses a cascading risk:


    1. Stolen credentials are resold multiple times through initial-access brokers and underground forums

    2. Each credential can enable multiple attack chains: lateral movement, data theft, ransomware deployment, financial fraud

    3. Time-lag exploitation: Credentials stolen weeks or months ago may still provide active access to networks


    ### Organizational Exposure


    Organizations should assume that any systems compromised during the Amadey/StealC operation may have been:

  • Backdoored with additional malware
  • Logged for credential theft
  • Monitored for lateral movement opportunities
  • Placed on IAB shopping lists for ransomware operators

  • ### The Ransomware Supply Chain


    This operation disrupts a critical link in the ransomware value chain:

  • Before: Amadey/StealC → Initial Access Brokers → Ransomware Operators
  • After: Ransomware operators must find alternative initial access vectors, increasing operational friction and complexity

  • ## Recommendations for Defenders


    ### Immediate Actions (Within 48 Hours)

  • Review breach notification databases using tools like Have I Been Pwned to determine if credentials from your organization appear in recovered datasets
  • Audit VPN and remote access logs from May 2026 and earlier for suspicious authentication patterns
  • Monitor for indicators of compromise (IOCs) associated with Amadey and StealC infrastructure

  • ### Short-Term Measures (Within 2 Weeks)

  • Force password resets for high-risk accounts (administrators, service accounts, shared credentials)
  • Implement credential stuffing detection to identify brute-force attempts using stolen credentials
  • Review MFA enforcement across all network access points
  • Scan systems for malware associated with Amadey or StealC using updated detection signatures from ESET, Proofpoint, and other partners

  • ### Long-Term Defensive Posture

  • Migrate from password-based authentication to passwordless methods (FIDO2 hardware keys, Windows Hello, biometric authentication)
  • Implement zero-trust architecture to minimize the damage from compromised credentials
  • Deploy behavioral analytics to detect unusual credential usage patterns
  • Establish credential rotation policies for service accounts and infrastructure access
  • Monitor initial-access broker forums through threat intelligence feeds to determine if your organization has been listed

  • ---


    ## HackWire Analysis


    Operation Endgame signals a critical inflection point in how law enforcement combats cybercrime: infrastructure disruption works, and it works fast. While individual threat actor prosecutions take years, dismantling the service platforms they depend on can be executed in coordinated strikes that multiply impact across an entire ecosystem.


    The €41 million in identified cryptocurrency and 27 million recovered credentials represent tangible damage to criminal operations, but the real significance lies in operational friction. Amadey and StealC operators must now rebuild C2 infrastructure, migrate their affiliate networks, establish new payment mechanisms, and regain trust from customers in a market that just witnessed their tools seized. That friction is expensive, time-consuming, and uncertain—exactly the conditions that reduce lower-tier cybercriminal activity while driving up costs for sophisticated operators.


    However, defenders should not interpret this as a permanent defeat of credential theft. The 27 million credentials recovered are almost certainly a subset of total credentials stolen—many may already be in underground circulation, and criminal groups typically maintain operational backups. The true measure of this operation's success will not be evident for 6-12 months, when we can assess whether credential-based initial access attacks have genuinely decreased or simply shifted to alternative stealer malware families.


    The private-sector participation—particularly Microsoft, ESET, and Proofpoint—demonstrates that cybersecurity vendors now function as quasi-law-enforcement infrastructure. Organizations should recognize that their own security tools are contributing to intelligence gathering that shapes global enforcement operations. This is a positive development for collective defense, but it also means that reporting suspicious activity to your security vendor is increasingly an act of public health, not just private protection.


    For defenders, the immediate lesson is stark: stolen credentials are now evidence of police action. If your credentials appear in breach notification services, assume they've been weaponized and prioritize remediation accordingly. The second lesson: infrastructure matters more than individual actors. Law enforcement's new focus on takedowns rather than arrests should encourage organizations to invest in architectural resilience and credential hygiene that doesn't depend on attackers being arrested—because credential-based attacks will persist regardless.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)