Operation Endgame takedown of Amadey and StealC infrastructure
Law Enforcement
Summary
Hide ▲
Show ▼
An international law-enforcement takedown under Operation Endgame disrupted shared infrastructure used by Amadey and StealC, with Microsoft, Europol, and international partners taking action against the malware operations. Authorities and private partners from multiple countries helped seize, block, sinkhole, and disrupt infrastructure tied to the malware families, including 326 servers and 142 domains. Europol said investigators identified more than €41 million in cryptocurrency linked to criminal activity and recovered about 27 million credentials stolen from over 385,000 compromised systems. Microsoft said the malware families were tied to more than 140,000 infected devices in May 2026.
Related Happenings
INTERPOL Operation First Light 2026 anti-fraud arrests and seizures
Law Enforcement
H score36
First: 09.07.2026 12:47
Last: 09.07.2026 12:47
Sources 1
About this happening:
INTERPOL coordinated Operation First Light 2026, a multinational anti-fraud crackdown spanning 97 countries and territories with support from agencies including China’s Ministry o...
INTERPOL Operation First Light 2026 anti-fraud arrests and seizures
Law EnforcementAbout this happening: INTERPOL coordinated Operation First Light 2026, a multinational anti-fraud crackdown spanning 97 countries and territories with support from agencies including China’s Ministry o...
Latest development: 09.07.2026 14:45
The enforcement phase from January 15 to April 30, 2026 turned Operation First Light 2026 into a cross-border crackdown on fraud and cybercrime. Early actions centered on scam networks, money laundering, and the blocking of illicit payments.
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor Meta
H score73
First: 24.06.2026 18:59
Last: 24.06.2026 18:59
Sources 1
How related:
All three malware families are known to be advertised under a malware-as-a-service (MaaS) model, allowing customers to deliver additional payloads or steal sensitive information from compromised hosts.
About this happening:
The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor MetaHow related: All three malware families are known to be advertised under a malware-as-a-service (MaaS) model, allowing customers to deliver additional payloads or steal sensitive information from compromised hosts.
About this happening: The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
StealC and Amadey infostealer infrastructure disruption
Malware Activity
H score69
First: 24.06.2026 18:25
Last: 24.06.2026 18:25
Sources 1
How related:
Both are infostealers with a dropper function that have been widely used by cybercriminals.
About this happening:
StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
StealC and Amadey infostealer infrastructure disruption
Malware ActivityHow related: Both are infostealers with a dropper function that have been widely used by cybercriminals.
About this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
Amadey and StealC shared-infrastructure malware activity
Malware Activity
H score66
First: 24.06.2026 18:02
Last: 24.06.2026 18:02
Sources 1
How related:
Amadey is a malware-as-a-service loader that gives threat actors access to systems, enabling them to deliver secondary payloads. StealC is an infostealer that has been around since 2023, helping cybercriminals obtain credentials, cryptocurrency wallets, cookies, and other valuable data.
About this happening:
The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...
Amadey and StealC shared-infrastructure malware activity
Malware ActivityHow related: Amadey is a malware-as-a-service loader that gives threat actors access to systems, enabling them to deliver secondary payloads. StealC is an infostealer that has been around since 2023, helping cybercriminals obtain credentials, cryptocurrency wallets, cookies, and other valuable data.
About this happening: The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...
AudiA6 laundering ecosystem and Dark2Web forum
Threat Actor Meta
H score31
First: 11.06.2026 18:55
Last: 11.06.2026 18:55
Sources 1
About this happening:
AudiA6 was disrupted as an industrial-scale cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks. Europol said the ecosystem lau...
AudiA6 laundering ecosystem and Dark2Web forum
Threat Actor MetaAbout this happening: AudiA6 was disrupted as an industrial-scale cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks. Europol said the ecosystem lau...
Timeline
-
24.06.2026 18:02 5 articles · 21d ago
Microsoft and partners disrupt shared Amadey and StealC infrastructure
Initial DisclosureMicrosoft, law enforcement, and cybersecurity partners disrupted shared infrastructure used by Amadey and StealC under Operation Endgame, targeting hundreds of domains and servers. Investigators used AI-powered analysis and a vulnerability in the StealC C&C panel to support the takedown, and Europol said the operation seized more than 25 million unique credentials from over 385,000 systems, identified and secured 18,000 compromised computers, and flagged crypto assets valued at more than $47 million.
Show sources
- Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware — www.securityweek.com — 24.06.2026 18:02
- Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware — www.securityweek.com — 24.06.2026 18:02
- Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers — www.infosecurity-magazine.com — 24.06.2026 18:25
- Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered — thehackernews.com — 24.06.2026 18:59
- Amadey, StealC malware operations disrupted in Operation Endgame action — www.bleepingcomputer.com — 24.06.2026 17:35