← All news

general

Operation Endgame Disrupts Amadey and StealC Malware

2026-06-25

Microsoft, Europol and a sprawling cast of partners have taken a hammer to the infrastructure behind two of the busier malware-as-a-service operations in circulation. Amadey and StealC, both rented out to criminals on subscription, saw 326 servers and 142 domains seized, blocked or sinkholed in the latest phase of Operation Endgame.

The numbers deserve a second look. Investigators traced roughly 41 million euros in crypto tied to criminal activity and recovered around 27 million stolen credentials lifted from more than 385,000 compromised machines. Microsoft's own filing in a US civil action says the two families alone were linked to over 140,000 infected devices in the first two weeks of May 2026.

Two tools, one production line

Amadey is the foot in the door. It's a loader, the malware that lands first and then pulls down whatever the buyer actually wants delivered, often ransomware. StealC does the looting: credentials, crypto wallets, browser data, anything with resale value.

Lately StealC has been the payload of choice for ClickFix and FileFix social engineering campaigns, including the run of fake TikTok tutorial videos that talk users into pasting attacker commands into their own machines. Once the credentials are out, they move through initial-access brokers to whoever's buying that week.

SocGholish caught in the same sweep

The operation also took aim at SocGholish, the fake browser update loader that has been quietly infecting visitors to compromised websites for years. It's one of those names that rarely makes mainstream headlines but turns up in incident reports with depressing regularity.

The private-sector roll call is long: ESET, Proofpoint, IBM X-Force, Bitsight, Infoblox, Shadowserver, Have I Been Pwned and Spamhaus among them. Law enforcement help came from Canada, Denmark, Germany, the Netherlands, the UK and the US.

The bit nobody likes talking about

Takedowns without arrests tend to be temporary. Previous Endgame phases have flattened DanaBot, Bumblebee, SmokeLoader and others. Most of those crews eventually rebuilt under new infrastructure, sometimes within weeks.

There's also the matter of what's already been stolen. Twenty-seven million credentials is a recovery number, not a containment number. Plenty more are sitting in spreadsheets and Telegram channels right now, being sorted, tested and resold. A login page that worked for an attacker last week will still work this week unless the password has changed and MFA is in the way.

So the quieter logs are a genuine win, and the disruption costs the operators real money to rebuild. But the credentials already harvested don't care that the servers are gone. They'll keep being tried against accounts for months, possibly years.

  • 326 servers and 142 domains taken offline, blocked or sinkholed
  • 41 million euros in crypto traced to criminal activity
  • 27 million credentials recovered from 385,000+ machines
  • 140,000+ devices linked to Amadey and StealC in just two weeks of May 2026

Worth a quiet cheer, then a check of whether your people are still reusing passwords across work and personal accounts. Because that's the spreadsheet entry that gets tried first.

Operation Endgame Disrupts Amadey and StealC Malware | RiskSense