StealC and Amadey infostealer infrastructure disruption
Malware Activity
Summary
Hide ▲
Show ▼
StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said the action seized or blocked around 50 domains and nearly 200 active IP-based C2 servers, while Microsoft said its court-authorized action disrupted more than 200 C2 servers and identified over 18,000 victim computers. The activity is tied to over 140,000 infected computers worldwide in the first two weeks of May 2026. The disruption reduces the malware supply chain used to steal credentials and deliver additional payloads.
Related Happenings
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor Meta
H score73
First: 24.06.2026 18:59
Last: 24.06.2026 18:59
Sources 1
How related:
All three malware families are known to be advertised under a malware-as-a-service (MaaS) model, allowing customers to deliver additional payloads or steal sensitive information from compromised hosts.
About this happening:
The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor MetaHow related: All three malware families are known to be advertised under a malware-as-a-service (MaaS) model, allowing customers to deliver additional payloads or steal sensitive information from compromised hosts.
About this happening: The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
Operation Endgame takedown of Amadey and StealC infrastructure
Law Enforcement
H score66
First: 24.06.2026 18:02
Last: 24.06.2026 18:02
Sources 1
How related:
The infrastructure of two infamous information stealer malware strains (infostealers), StealC and Amadey, has been disrupted by an international law enforcement takedown.
About this happening:
An international law-enforcement takedown under Operation Endgame disrupted shared infrastructure used by Amadey and StealC, with Microsoft, Europol, and i...
Operation Endgame takedown of Amadey and StealC infrastructure
Law EnforcementHow related: The infrastructure of two infamous information stealer malware strains (infostealers), StealC and Amadey, has been disrupted by an international law enforcement takedown.
About this happening: An international law-enforcement takedown under Operation Endgame disrupted shared infrastructure used by Amadey and StealC, with Microsoft, Europol, and i...
Amadey and StealC shared-infrastructure malware activity
Malware Activity
H score66
First: 24.06.2026 18:02
Last: 24.06.2026 18:02
Sources 1
About this happening:
The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...
Amadey and StealC shared-infrastructure malware activity
Malware ActivityAbout this happening: The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...
Operation Endgame international cybercrime disruption initiative
Public Sector Action
H score57
First: 19.06.2026 18:07
Last: 19.06.2026 18:07
Sources 1
About this happening:
Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Operation Endgame international cybercrime disruption initiative
Public Sector ActionAbout this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Backdoor.Turn Microsoft Teams TURN relay malware activity
Malware Activity
H score29
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
Backdoor.Turn is a Go-based RAT tied to DragonForce ransomware operators that hid command-and-control traffic through Microsoft Teams TURN relay infrastructure dur...
Backdoor.Turn Microsoft Teams TURN relay malware activity
Malware ActivityAbout this happening: Backdoor.Turn is a Go-based RAT tied to DragonForce ransomware operators that hid command-and-control traffic through Microsoft Teams TURN relay infrastructure dur...
Timeline
-
24.06.2026 18:25 4 articles · 21d ago
Operation Endgame disrupts StealC and Amadey infrastructure
Initial DisclosureEuropol said Operation Endgame disrupted the StealC and Amadey infostealer infrastructure, coordinated with Germany’s Federal Criminal Police Office and supported by Eurojust, EC3 and industry partners including Microsoft, ESET, BitSight, IBM X-Force, Lumen, Mitsui Bussan Secure Directions and Proofpoint. The takedown seized around 50 domains and nearly 200 active IP-based C2 servers linked to the two malware families; Microsoft said its court-authorized action disrupted more than 200 C2 servers, identified over 18,000 victim computers, and linked Amadey and StealC to over 140,000 infected computers worldwide in the first two weeks of May 2026.
Show sources
- Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers — www.infosecurity-magazine.com — 24.06.2026 18:25
- Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers — www.infosecurity-magazine.com — 24.06.2026 18:25
- Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered — thehackernews.com — 24.06.2026 18:59
- Amadey, StealC malware operations disrupted in Operation Endgame action — www.bleepingcomputer.com — 24.06.2026 17:35