# Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware in Major Operation Endgame Strike
A coordinated takedown operation involving Microsoft, Europol, law enforcement agencies, and seven major cybersecurity firms has dismantled the shared command-and-control infrastructure supporting two of the world's most prolific malware families: Amadey and StealC. The action, announced on June 24, 2026, represents a historic shift in law enforcement strategy — moving beyond targeting individual threats to disrupting the entire "cybercrime assembly line" that enables attacks to scale globally.
The operation disrupted hundreds of domains and servers, seized credentials from over 385,000 compromised systems, and flagged $47 million in cryptocurrency assets for seizure. Eighteen thousand infected computers were identified and secured, marking one of the largest coordinated takedowns in recent cybersecurity history.
## The Threat: A Perfect Malware Partnership
Amadey and StealC represent two complementary weapons in the hands of cybercriminals. Amadey, which has been circulating since 2018, operates as a malware-as-a-service (MaaS) loader — a tool that gives threat actors initial access to compromised systems and enables them to deliver secondary payloads on demand. Think of it as an entry point or foothold creation tool.
StealC, a relative newcomer that emerged in 2023, serves as an infostealer designed to exfiltrate valuable data from infected systems, including:
Together, these malware families form a potent combination: Amadey breaches the perimeter, and StealC harvests everything of value inside.
## Operation Endgame: A New Strategic Approach
This takedown is the latest high-profile action under Operation Endgame, a multi-year initiative launched by Europol and law enforcement partners to dismantle major cybercriminal infrastructure. What distinguishes this particular operation is the methodology and scope.
"This operation marked a shift in strategy," Europol stated. "Instead of focusing solely on individual threats, we disrupted the entire chain that allows cyberattacks to scale."
Rather than hunting down individual victims or pursuing specific threat actors, law enforcement and cybersecurity partners targeted the shared infrastructure that enabled both malware families to operate efficiently — the command-and-control servers that operators use to manage infected systems and coordinate attacks.
Key partners in the operation included:
| Organization | Role |
|---|---|
| Microsoft | AI analysis and infrastructure mapping |
| Europol | Coordination and legal oversight |
| ESET | Threat intelligence and analysis |
| Bitsight | Risk assessment and victim identification |
| IBM X-Force | Incident response and forensics |
| Proofpoint | Email-based threat intelligence |
| Mitsui Bussan Secure Directions (MBSD) | Japan-based partner coordination |
## Technical Innovation: AI-Powered Infrastructure Mapping
One of the operation's key breakthroughs was the use of AI-powered analysis to identify the shared infrastructure connecting Amadey and StealC. By analyzing communication patterns, command structures, and network dependencies, Microsoft's AI systems identified that despite appearing as separate malware families, both relied on the same backend infrastructure — a critical vulnerability in the criminals' operational security.
Additionally, researchers discovered a critical vulnerability in the StealC command-and-control panel itself: the ability to upload arbitrary web shells to the server. Law enforcement exploited this vulnerability to gather evidence and coordinate the takedown. Notably, evidence suggests that some StealC affiliates had already discovered this same flaw and were using it to steal data from rival affiliates — highlighting the inherent untrustworthiness within cybercriminal ecosystems.
## Scale of the Disruption
The operation's impact was staggering:
To put this in perspective, the credentials seized represent roughly the population of Australia — each one a potential gateway to corporate networks, financial accounts, and personal data for millions of individuals.
## Background: Years of Unchecked Growth
Amadey's eight-year operational history demonstrates how persistent malware infrastructure can become when left unchecked. Since 2018, the loader has been continuously distributed through malspam campaigns, drive-by downloads, and affiliate networks, establishing it as a reliable tool for initial system compromise.
StealC, though newer (launching in 2023), quickly became one of the most widely deployed infostealers in use. Its distributed as a service offering meant that low-skill attackers could deploy powerful data-harvesting capabilities without needing advanced technical knowledge.
The partnership between these two families was born of necessity — threat actors discovered that deploying them together created a complete attack chain: intrude, establish persistence, steal data, monetize through credential sales or ransom.
## Implications for Organizations and Users
This takedown carries several important implications:
For Organizations:
For Users:
For Security Teams:
## The Broader Context: Operation Endgame's Momentum
This operation follows closely on the heels of the takedown of the SocGholish botnet and represents a clear escalation in the sophistication and scale of law enforcement's approach to cybercrime infrastructure. Rather than arresting individual operators (which often leads to replacement), authorities are learning to identify and eliminate the shared infrastructure that enables entire ecosystems of cybercriminals to operate.
The use of vulnerability exploitation, AI analysis, and international coordination signals a maturation of law enforcement's cyber capabilities.
---
## HackWire Analysis
This takedown reveals a critical shift in how law enforcement thinks about cybercrime: the "cybercrime assembly line" concept is the insight that matters. Amadey and StealC succeeded not because of technical sophistication but because they solved two distinct problems—initial access and data exfiltration—in a way that plugged seamlessly into each other and countless affiliate networks. By focusing on the *infrastructure glue* rather than the malware variants themselves, authorities have struck at something far more difficult to replace than code.
The $47 million in flagged cryptocurrency is attention-grabbing, but the real victory is the seizure of 25+ million credentials—each one representing potential compromise across corporate networks, SaaS applications, and financial accounts. For defenders, the unsettling takeaway is that if your organization wasn't running behavioral EDR or had unpatched systems between 2018 and 2026, you're statistically likely among the compromised. The notion that "we probably weren't hit" is mathematically indefensible given the scale.
What's also notable—and underreported in mainstream coverage—is the vulnerability Microsoft and partners discovered in the StealC C&C panel. The fact that threat actors themselves had already weaponized it to steal from each other exposes the fundamental fragility of trust in criminal enterprises. Law enforcement doesn't need to be smarter than individual attackers; it needs to be smart enough to exploit the structural weaknesses that arise when criminal infrastructure prioritizes scale over security.
One caution: takedowns are temporary disruptions unless the underlying victim base shrinks. Amadey and StealC will likely relaunch on alternate infrastructure; the real test is whether this operation disrupts the distribution chains and affiliate networks that feed them fresh victims. Early reports suggest significant traffic shifts, but full assessment will take months.
— HackWire Editorial
---
## Related Coverage