[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQZcWSNvohOicTiw1GLSJoZCg2CHugNVXgE-nbMDtTUA":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"ce6a2c10-5c49-4b70-b147-d29bf1dadab5","Amadey, StealC malware operations disrupted in Operation Endgame action","amadey-stealc-malware-operations-disrupted-in-operation-endgame-action-5140e8","Microsoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. [...]","Operation Endgame, a multinational law enforcement effort involving Europol and Microsoft, has successfully disrupted the Amadey and StealC malware operations. The action led to the seizure of over €41 million in cryptocurrency, the recovery of 27 million stolen credentials, and the disruption of 326 servers and 142 domains. The operation targeted the infrastructure used by these malware-as-a-service operations, which are instrumental in initial access, credential theft, and subsequent ransomware deployment.","Operation Endgame disrupts Amadey and StealC malware operations, seizing crypto and credentials.","Amadey, StealC malware operations disrupted in Operation Endgame action By Lawrence Abrams June 24, 2026 10:35 AM 0 Microsoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. The law enforcement action involved authorities and private partners from multiple countries, who assisted in identifying and taking down, seizing, blocking, or sinkholing infrastructure tied to the malware families. According to Europol, the operation resulted in the disruption of 326 servers and 142 domains, Investigators also identified more than €41 million ($47 million) in cryptocurrency linked to criminal activity and recovered approximately 27 million credentials stolen from over 385k compromised systems. \"By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cybercriminals, making it harder for attacks to succeed, spread, or recover,\" announced Europol. The coordinated action also targeted SocGholish (FakeUpdates), a malware loader that infects visitors via compromised websites that serve fake browser update prompts. Operation Endgame included law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States, with Europol and Eurojust coordinating the effort. Private-sector support was provided by Microsoft, ESET, Proofpoint, IBM X-Force, Bitsight, Infoblox, Orange Cyberdefense, Shadowserver, Have I Been Pwned, Spamhaus, and others. According to Europol, the operation focused on disrupting cybercrime infrastructure that threat actors utilize to gain initial access to systems, steal credentials, and ultimately deploy ransomware or conduct financial fraud. Amadey and StealC are sold to cybercriminals through malware-as-a-service operations, where affiliates pay for access to malware builders, management panels, support, and infrastructure. Criminals use Amadey to gain an initial foothold on victim devices to deploy additional malware. StealC is used to steal credentials, cryptocurrency wallets, and other sensitive information that can later be sold or leveraged in ransomware attacks. Amadey is a malware botnet used by both ransomware gangs and state-sponsored hacking groups to breach networks. More recently, StealC has been widely used in a variety of ClickFix attacks, such as fake instructional videos on TikTok and FileFix attacks. In a civil action filed by Microsoft in the US, Microsoft's Digital Crimes Unit said it identified more than 200 malicious command-and-control domains and IP addresses associated with Amadey and StealC and worked with partners to shut down the infrastructure through court orders, domain seizures, registrations, and provider notifications. According to Microsoft's complaint, stolen credentials harvested through StealC are commonly sold on underground marketplaces and through initial-access brokers (IABs). These credentials are then used by other threat actors to breach networks, steal data, and deploy ransomware. The company said the two malware families were linked to more than 140,000 infected devices during the first two weeks of May 2026 alone. Other private partners released reports on their involvement in the disruption. Security vendor ESET said it assisted the operation by identifying and disrupting the infrastructure used by both malware families. The company reported that the action affected roughly 50 domains used by the operations and nearly 200 active command-and-control servers. Proofpoint and IBM X-Force also contributed intelligence and malware analysis supporting the disruption. Bitsight said it assisted the operation by identifying and analyzing infrastructure associated with both malware families, helping investigators map servers and related command-and-control infrastructure used by the threat actors. The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader. Unfortunately, unless arrests are made in the operations, the threat actors commonly rebuild infrastructure to launch new attacks. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: Police cleans nearly 15,000 SocGholish-infected sites tied to Evil CorpStealthy Mistic backdoor linked to ransomware access broker KongTukeWhatsApp phishing attack uses fake business docs to hack PCsAryStinger botnet infected thousands of D-Link routers worldwideUSB worm spreads crypto-stealing malware via Windows shortcut files","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Famadey-stealc-malware-operations-disrupted-in-operation-endgame-action\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2022\u002F05\u002F05\u002Fmalware-header.jpg","2026-06-24T14:35:11+00:00","2026-06-24T16:00:24.618761+00:00",9,[18,21],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"Operation Endgame","campaign","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":26,"name":27,"slug":28},null,"Malware","malware",[30,35,37,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48,51,53,56],{"type":28,"value":49,"context":50},"Amadey","Malware family disrupted in Operation Endgame.",{"type":28,"value":52,"context":50},"StealC",{"type":28,"value":54,"context":55},"SocGholish","Malware loader targeted in Operation Endgame.",{"type":28,"value":57,"context":58},"FakeUpdates","Alternative name for SocGholish malware loader."]