Microsoft, Europol and partners disrupt shared Amadey and StealC malware infrastructure in Operation Endgame

Microsoft, Europol, and industry partners said they disrupted hundreds of domains and command-and-control servers used by the Amadey loader and StealC infostealer malware families. The action was part of Operation Endgame and targeted shared infrastructure identified through analysis of both malware families; authorities said they seized more than 25 million stolen credentials from over 385,000 systems, identified 18,000 compromised computers, and also used a vulnerability in the StealC control panel to support the takedown.
Why it matters: This matters because Amadey and StealC are widely used to break into computers and steal passwords, cookies, and crypto-wallet data at scale. Organizations should hunt for signs of these malware families, rotate exposed credentials, and check endpoints for infostealer or loader infections if they may have been affected.

Sources

Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement
2026.06.24 98% relevant
This article covers the same takedown event and adds concrete scope details: 326 servers and 142 domains dismantled, €41 million in suspected criminal crypto assets identified, 27 million stolen credentials reclaimed, and Microsoft's statement that AI analysis linked Amadey and StealC to shared infrastructure.
Microsoft uses AI to link two malware operations in racketeering suit
2026.06.24 97% relevant
This article is a direct update on the same takedown, adding that Microsoft used Copilot and other AI tools to connect StealC and Amadey through shared infrastructure, enabling a RICO-based racketeering suit against five defendants. It also reiterates the scale of the disruption: 200+ domains/C2 servers, about 27 million recovered stolen credentials, and more than $47 million in flagged or restricted crypto assets when combined with the related SocGholish action.
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
info@thehackernews.com (The Hacker News) 2026.06.24 98% relevant
This is the same Operation Endgame event targeting the shared Amadey and StealC malware network, adding reporting that 27 million stolen credentials were recovered and reinforcing the scope and impact of the disruption.
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
Eduard Kovacs 2026.06.24 100% relevant
This article establishes a distinct law-enforcement and industry takedown of the shared infrastructure behind the Amadey and StealC malware ecosystem, separate from previously tracked Operation Endgame actions against SocGholish.
← Back to all stories