# Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware in Major Operation Endgame Strike


A coordinated takedown operation involving Microsoft, Europol, law enforcement agencies, and seven major cybersecurity firms has dismantled the shared command-and-control infrastructure supporting two of the world's most prolific malware families: Amadey and StealC. The action, announced on June 24, 2026, represents a historic shift in law enforcement strategy — moving beyond targeting individual threats to disrupting the entire "cybercrime assembly line" that enables attacks to scale globally.


The operation disrupted hundreds of domains and servers, seized credentials from over 385,000 compromised systems, and flagged $47 million in cryptocurrency assets for seizure. Eighteen thousand infected computers were identified and secured, marking one of the largest coordinated takedowns in recent cybersecurity history.


## The Threat: A Perfect Malware Partnership


Amadey and StealC represent two complementary weapons in the hands of cybercriminals. Amadey, which has been circulating since 2018, operates as a malware-as-a-service (MaaS) loader — a tool that gives threat actors initial access to compromised systems and enables them to deliver secondary payloads on demand. Think of it as an entry point or foothold creation tool.


StealC, a relative newcomer that emerged in 2023, serves as an infostealer designed to exfiltrate valuable data from infected systems, including:


  • Credentials (usernames and passwords)
  • Cryptocurrency wallets and private keys
  • Browser cookies and session tokens
  • Payment card information
  • Authentication credentials for cloud services

  • Together, these malware families form a potent combination: Amadey breaches the perimeter, and StealC harvests everything of value inside.


    ## Operation Endgame: A New Strategic Approach


    This takedown is the latest high-profile action under Operation Endgame, a multi-year initiative launched by Europol and law enforcement partners to dismantle major cybercriminal infrastructure. What distinguishes this particular operation is the methodology and scope.


    "This operation marked a shift in strategy," Europol stated. "Instead of focusing solely on individual threats, we disrupted the entire chain that allows cyberattacks to scale."


    Rather than hunting down individual victims or pursuing specific threat actors, law enforcement and cybersecurity partners targeted the shared infrastructure that enabled both malware families to operate efficiently — the command-and-control servers that operators use to manage infected systems and coordinate attacks.


    Key partners in the operation included:


    | Organization | Role |

    |---|---|

    | Microsoft | AI analysis and infrastructure mapping |

    | Europol | Coordination and legal oversight |

    | ESET | Threat intelligence and analysis |

    | Bitsight | Risk assessment and victim identification |

    | IBM X-Force | Incident response and forensics |

    | Proofpoint | Email-based threat intelligence |

    | Mitsui Bussan Secure Directions (MBSD) | Japan-based partner coordination |


    ## Technical Innovation: AI-Powered Infrastructure Mapping


    One of the operation's key breakthroughs was the use of AI-powered analysis to identify the shared infrastructure connecting Amadey and StealC. By analyzing communication patterns, command structures, and network dependencies, Microsoft's AI systems identified that despite appearing as separate malware families, both relied on the same backend infrastructure — a critical vulnerability in the criminals' operational security.


    Additionally, researchers discovered a critical vulnerability in the StealC command-and-control panel itself: the ability to upload arbitrary web shells to the server. Law enforcement exploited this vulnerability to gather evidence and coordinate the takedown. Notably, evidence suggests that some StealC affiliates had already discovered this same flaw and were using it to steal data from rival affiliates — highlighting the inherent untrustworthiness within cybercriminal ecosystems.


    ## Scale of the Disruption


    The operation's impact was staggering:


  • 25+ million unique credentials stolen from compromised systems were seized and secured
  • 385,000+ systems identified as compromised by these malware families
  • 18,000 compromised computers successfully secured through remediation efforts
  • $47 million in cryptocurrency assets identified and flagged for restriction
  • Hundreds of domains and servers disrupted in the takedown

  • To put this in perspective, the credentials seized represent roughly the population of Australia — each one a potential gateway to corporate networks, financial accounts, and personal data for millions of individuals.


    ## Background: Years of Unchecked Growth


    Amadey's eight-year operational history demonstrates how persistent malware infrastructure can become when left unchecked. Since 2018, the loader has been continuously distributed through malspam campaigns, drive-by downloads, and affiliate networks, establishing it as a reliable tool for initial system compromise.


    StealC, though newer (launching in 2023), quickly became one of the most widely deployed infostealers in use. Its distributed as a service offering meant that low-skill attackers could deploy powerful data-harvesting capabilities without needing advanced technical knowledge.


    The partnership between these two families was born of necessity — threat actors discovered that deploying them together created a complete attack chain: intrude, establish persistence, steal data, monetize through credential sales or ransom.


    ## Implications for Organizations and Users


    This takedown carries several important implications:


    For Organizations:

  • If your systems were compromised between 2018-2026, there is a high likelihood your credentials may be among the 25+ million seized. Assume compromise and reset credentials across all critical systems.
  • Monitor for fraudulent login attempts, account takeovers, and lateral movement suspicious activity in your environment.
  • Conduct a comprehensive audit of systems that may have been running outdated software or lacking endpoint detection capabilities.

  • For Users:

  • If your personal passwords or cryptocurrency wallets were stolen, begin credential rotation immediately.
  • Monitor financial accounts, credit reports, and email accounts for suspicious activity.
  • Enable multi-factor authentication on all critical accounts to prevent credential-based takeovers.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus if you notice unauthorized activity.

  • For Security Teams:

  • These takedowns demonstrate the effectiveness of coordinated public-private partnerships. Report suspected compromises to law enforcement and work with vendors on collective defense strategies.
  • Prioritize detection of credential theft and unusual authentication patterns in your environment.
  • Deploy advanced endpoint detection capabilities that can identify infostealer behavior.

  • ## The Broader Context: Operation Endgame's Momentum


    This operation follows closely on the heels of the takedown of the SocGholish botnet and represents a clear escalation in the sophistication and scale of law enforcement's approach to cybercrime infrastructure. Rather than arresting individual operators (which often leads to replacement), authorities are learning to identify and eliminate the shared infrastructure that enables entire ecosystems of cybercriminals to operate.


    The use of vulnerability exploitation, AI analysis, and international coordination signals a maturation of law enforcement's cyber capabilities.


    ---


    ## HackWire Analysis


    This takedown reveals a critical shift in how law enforcement thinks about cybercrime: the "cybercrime assembly line" concept is the insight that matters. Amadey and StealC succeeded not because of technical sophistication but because they solved two distinct problems—initial access and data exfiltration—in a way that plugged seamlessly into each other and countless affiliate networks. By focusing on the *infrastructure glue* rather than the malware variants themselves, authorities have struck at something far more difficult to replace than code.


    The $47 million in flagged cryptocurrency is attention-grabbing, but the real victory is the seizure of 25+ million credentials—each one representing potential compromise across corporate networks, SaaS applications, and financial accounts. For defenders, the unsettling takeaway is that if your organization wasn't running behavioral EDR or had unpatched systems between 2018 and 2026, you're statistically likely among the compromised. The notion that "we probably weren't hit" is mathematically indefensible given the scale.


    What's also notable—and underreported in mainstream coverage—is the vulnerability Microsoft and partners discovered in the StealC C&C panel. The fact that threat actors themselves had already weaponized it to steal from each other exposes the fundamental fragility of trust in criminal enterprises. Law enforcement doesn't need to be smarter than individual attackers; it needs to be smart enough to exploit the structural weaknesses that arise when criminal infrastructure prioritizes scale over security.


    One caution: takedowns are temporary disruptions unless the underlying victim base shrinks. Amadey and StealC will likely relaunch on alternate infrastructure; the real test is whether this operation disrupts the distribution chains and affiliate networks that feed them fresh victims. Early reports suggest significant traffic shifts, but full assessment will take months.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Botnets](https://www.hackwire.news/category/botnets) and [Law Enforcement](https://www.hackwire.news/category/law-enforcement)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)