Microsoft, Europol, law enforcement agencies, and multiple private-sector partners carried out a coordinated disruption of the StealC infostealer and Amadey loader ecosystems, using court orders and related legal actions to target both malware operations at once. The operation struck a broad criminal infrastructure spanning more than 200 command-and-control domains and IP addresses, with partner reporting citing 66 domains and 296 servers tied to the two services. Microsoft said the malware families were linked to more than 140,000 infected computers in a single week in May, while partner investigators reported the seizure of 25.6 million unique credentials stolen from more than 385,000 compromised systems.
Investigators said StealC, active since 2023 as a malware-as-a-service infostealer, was used to steal browser data, credentials, email and messaging data, VPN and cloud access, and cryptocurrency wallet information, while Amadey, active since 2018, functioned as a modular loader and backdoor that frequently delivered StealC and other payloads. Researchers also identified a vulnerability in the StealC command-and-control panel that helped support search-and-seizure actions, and they used configuration extraction and a custom emulator to map affiliate activity and delivery chains. The two malware families were described as part of a broader cybercrime ecosystem tied to credential theft, access brokering, and downstream attacks including ransomware, with observed links to payloads such as AsyncRAT, RedLine, Vidar, XMRig, and in one case LockBit Black.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
Europol said the June 2026 Operation Endgame action recovered 27 million compromised data sets tied to the SocGholish, Amadey, and StealC malware ecosystems. This added a new measure of the operation’s impact beyond previously disclosed credential seizures and infrastructure takedowns.
Shadowserver published a one-off StealC Historical Bot Infection Special Report based on Dutch NHTCU data, covering infections from 2025-07-04 to 2026-06-16. The report documented tens of millions of StealC theft events affecting victims across 231 countries or territories.
Hackread reported that the developers of StealC patched the directory traversal vulnerability in the malware’s command-and-control panel in February 2026. The flaw had been used during investigative and disruption activity tied to Operation Endgame.
As part of the June 2026 disruption of the Amadey and StealC ecosystem, authorities said they identified and secured 18,000 compromised computers and flagged more than $47 million in cryptocurrency assets. This expanded the publicly disclosed impact of the operation beyond infrastructure takedowns and credential seizures.
In June 2026, Microsoft, Europol, law enforcement, and industry partners carried out a coordinated disruption targeting the StealC and Amadey ecosystem. The action targeted more than 200 command-and-control servers, including 66 domains and 296 servers, using court orders, seizures, registrations, and provider notifications.
Microsoft said Amadey and StealC were associated with more than 140,000 infected computers worldwide in the first week of May alone, underscoring the scale of the malware ecosystem.
Sources described StealC as a malware-as-a-service infostealer active since 2023, with one reference specifying January 2023. It steals credentials and other sensitive data and is also used in broader malware delivery chains.
Microsoft described Amadey as a malware-as-a-service loader that has been active since 2018 and is commonly used in cybercrime operations, including attacks on Ukraine.
Europol said the coordinated June 2026 Operation Endgame action seized more than EUR 41 million in criminal cryptocurrency assets tied to the SocGholish, Amadey, and StealC malware ecosystems. This added a specific asset-seizure outcome beyond previously reported infrastructure takedowns and flagged crypto holdings.
In its June 24, 2026 Operation Endgame write-up, ESET said it identified 53 Amadey clusters and 73 StealC clusters from three years of tracking. The disclosure highlighted that both malware-as-a-service ecosystems were fragmented, with affiliates operating their own command-and-control infrastructure rather than relying on centrally managed servers.
IBM X-Force and Proofpoint said they built a StealC emulator to extract configurations, identify infrastructure, and collect secondary payloads from StealC infections. Their analysis showed StealC was used not only for credential theft but also to deliver malware including AsyncRAT, RedLine, Vidar, XTinyLoader, and in one case LockBit Black ransomware.
Microsoft released technical analysis, detection guidance, mitigations, and indicators of compromise for StealC and Amadey, including hashes and command-and-control URLs.
In the June 24, 2026 reporting on Operation Endgame, Europol linked the SocGholish malware operation to the Russian cybercrime group Evil Corp. This added an attribution detail to the broader disruption of SocGholish, Amadey, and StealC infrastructure.
Europol said login credentials obtained through the earlier SocGholish disruption were added to the Have I Been Pwned breach-notification database. This represented a follow-on victim notification step within the broader Operation Endgame effort.
Europol said the June 2026 Operation Endgame action also heavily impacted SocGholish-linked infrastructure, including remediation of 14,971 infected websites. This expanded the publicly disclosed scope of the disruption beyond Amadey and StealC to include SocGholish malware distribution infrastructure.
Microsoft said its civil racketeering case names five defendants allegedly involved in a single malware-as-a-service enterprise spanning the StealC and Amadey operations. The filing accompanied the broader June 2026 disruption effort targeting shared infrastructure used by both malware families.
On June 24, 2026, Microsoft’s Digital Crimes Unit announced a coordinated disruption with Europol and industry partners targeting the domains and command-and-control infrastructure supporting StealC and Amadey. Microsoft said it identified more than 200 malicious domains and IP addresses and moved to shut them down.
Microsoft said Amadey and StealC were linked to more than 140,000 infected devices worldwide during the first two weeks of May 2026. This broadened the previously disclosed time window for the scale of infections associated with the malware ecosystem.
The reference says Operation Endgame was launched in 2024 as an international effort to dismantle criminal cyber services. This provides earlier origin context for the later June 2026 actions against the Amadey and StealC ecosystems.
As part of the June 2026 Operation Endgame action, authorities seized more than 25.6 million unique credentials stolen from over 385,000 compromised systems tied to the StealC ecosystem.
Proofpoint and IBM X-Force said researchers found a vulnerability in the StealC command-and-control panel, which enabled law enforcement to support search-and-seizure actions against StealC servers.
Authorities said the coordinated Operation Endgame action targeting the Amadey and StealC malware ecosystems was carried out from June 15 to 19, 2026. The operation involved international law enforcement and private-sector partners as part of the broader disruption campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
38 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcezdnet.fr
Open sourcerisky.biz
Open sourcetechrepublic.com
Open sourceflashpoint.io
Open sourceblog.talosintelligence.com
Open sourceblogs.microsoft.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.