Find notable cyber news and cases, enriched with sources, timelines, and signals.

Operation Endgame takedown of Amadey and StealC infrastructure

Law Enforcement
First reported
Last updated
Happening score
H score 66
4 unique sources, 4 articles

Summary

Hide ▲

An international law-enforcement takedown under Operation Endgame disrupted shared infrastructure used by Amadey and StealC, with Microsoft, Europol, and international partners taking action against the malware operations. Authorities and private partners from multiple countries helped seize, block, sinkhole, and disrupt infrastructure tied to the malware families, including 326 servers and 142 domains. Europol said investigators identified more than €41 million in cryptocurrency linked to criminal activity and recovered about 27 million credentials stolen from over 385,000 compromised systems. Microsoft said the malware families were tied to more than 140,000 infected devices in May 2026.

Related Happenings

INTERPOL Operation First Light 2026 anti-fraud arrests and seizures

Law Enforcement
H score36 First: 09.07.2026 12:47 Last: 09.07.2026 12:47 Sources 1

About this happening: INTERPOL coordinated Operation First Light 2026, a multinational anti-fraud crackdown spanning 97 countries and territories with support from agencies including China’s Ministry o...

Latest development: 09.07.2026 14:45

The enforcement phase from January 15 to April 30, 2026 turned Operation First Light 2026 into a cross-border crackdown on fraud and cybercrime. Early actions centered on scam networks, money laundering, and the blocking of illicit payments.

Amadey and StealC MaaS ecosystem and affiliate model

Threat Actor Meta
H score73 First: 24.06.2026 18:59 Last: 24.06.2026 18:59 Sources 1

How related: All three malware families are known to be advertised under a malware-as-a-service (MaaS) model, allowing customers to deliver additional payloads or steal sensitive information from compromised hosts.

About this happening: The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...

StealC and Amadey infostealer infrastructure disruption

Malware Activity
H score69 First: 24.06.2026 18:25 Last: 24.06.2026 18:25 Sources 1

How related: Both are infostealers with a dropper function that have been widely used by cybercriminals.

About this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...

Amadey and StealC shared-infrastructure malware activity

Malware Activity
H score66 First: 24.06.2026 18:02 Last: 24.06.2026 18:02 Sources 1

How related: Amadey is a malware-as-a-service loader that gives threat actors access to systems, enabling them to deliver secondary payloads. StealC is an infostealer that has been around since 2023, helping cybercriminals obtain credentials, cryptocurrency wallets, cookies, and other valuable data.

About this happening: The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...

AudiA6 laundering ecosystem and Dark2Web forum

Threat Actor Meta
H score31 First: 11.06.2026 18:55 Last: 11.06.2026 18:55 Sources 1

About this happening: AudiA6 was disrupted as an industrial-scale cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks. Europol said the ecosystem lau...

Timeline

  1. 24.06.2026 18:02 5 articles · 21d ago

    Microsoft and partners disrupt shared Amadey and StealC infrastructure

    Initial Disclosure

    Microsoft, law enforcement, and cybersecurity partners disrupted shared infrastructure used by Amadey and StealC under Operation Endgame, targeting hundreds of domains and servers. Investigators used AI-powered analysis and a vulnerability in the StealC C&C panel to support the takedown, and Europol said the operation seized more than 25 million unique credentials from over 385,000 systems, identified and secured 18,000 compromised computers, and flagged crypto assets valued at more than $47 million.

    Show sources