CTIPilot

Operation Endgame, Amadey/StealC takedown

campaign · campaign:operation-endgame-amadey-stealc

Operation Endgame law-enforcement action dismantling the Amadey and StealC malware-as-a-service infrastructure.

Coverage timeline
2
first 2026-06-19 → last 2026-06-25
Peak priority
high
2 high
Sources cited
8
7 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
3
pinned v19.2 · see below
2026-06-192 appearances2026-06-25

ATT&CK techniques

3 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

Story timeline

  1. 2026-06-25Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
    active-threats
  2. 2026-06-19Operation Endgame expands to SocGholish/TA569, 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites
    active-threats

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

includes

Where this entity is cited

  • active-threats2

Source distribution

  • proofpoint.com2 (25%)
  • bleepingcomputer.com1 (12%)
  • europol.europa.eu1 (12%)
  • helpnetsecurity.com1 (12%)
  • microsoft.com1 (12%)
  • politie.nl1 (12%)
  • welivesecurity.com1 (12%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Operation Endgame, Amadey/StealC takedown (2)

2026-06-25 · view entry permalink →

HIGH

Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone

A Europol-coordinated law-enforcement and private-sector action on 24 June 2026 took down the shared infrastructure of Amadey and StealC, two of the dominant commodity malware-as-a-service families that form the pre-ransomware infection chain (Microsoft, 2026-06-24 · Europol, 2026-06-24). 326 servers and 142 domains were seized, ~27 million credentials stolen from 385,000+ systems recovered, and EUR 41M in crypto frozen (BleepingComputer, 2026-06-24). Amadey (active since 2018) is a modular C++ loader with 29+ commands, scheduled-task persistence and payload staging; StealC is a C++ infostealer-MaaS harvesting browser credentials, cookies, wallets and desktop clients over RC4-encrypted HTTP. ESET contributed RC4 keys and clustering that identified 53 Amadey and 73 StealC clusters (ESET, 2026-06-24); Proofpoint and IBM X-Force documented a directory-traversal flaw in StealC's C2 panel (its filename sanitiser failed to strip forward-slashes), and an exploit built on it was used by global law enforcement to map and access affiliate infrastructure (Proofpoint/IBM X-Force, 2026-06-24). This is a distinct action from the SocGholish/TA569 phase covered on 2026-06-19. Why it matters to us: Detecting Amadey delivery (ClickFix fake-CAPTCHA, SEO poisoning) and StealC exfiltration is a real ransomware pre-emption opportunity. Hunt scheduled-task creation (EID 4698) by browser/Office parents from %APPDATA% paths, and browser-process → mshta.exe/wscript.exe chains with temp-path arguments.

326 servers and 142 domains while identifying €41 million in cryptocurrency tied to criminal activity. Investigators recovered approximately 27 million credentials stolen from over 385,000 compromised systems

BleepingComputer

Amadey has been active in the crimeware ecosystem since 2018 and functions as a modular backdoor with access to more than 29 backdoor commands and a wide variety of plugins

Microsoft Threat Intelligence
threat25 Jun 04:59Zmulti-sourceOpen finding ↗

2026-06-19 · view entry permalink →

HIGH

Operation Endgame expands to SocGholish/TA569, 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites

A coordinated law-enforcement action on 2026-06-18 (an expansion of the May 2024 Operation Endgame) dismantled infrastructure tied to TA569, the long-running operator of the SocGholish (FakeUpdates) initial-access framework (Politie, 2026-06-18; Help Net Security, 2026-06-18). The Dutch National High Tech Crime Unit led the operation with the RCMP, FBI, BKA and Europol; 106 command-and-control servers were taken down and the malicious JavaScript loader was removed from 14,971 compromised WordPress sites. SocGholish injects obfuscated JavaScript into legitimate WordPress sites (typically via stolen wp-admin credentials or vulnerable plugins), fingerprints visitors and renders a fake browser-update lure; accepting it drives a ZIP download of a .js/.lnk stage-1 that executes through wscript.exe or mshta.exe (T1189 Drive-by Compromise → T1059.007 JavaScript → T1204.002 User Execution), historically passing access to Evil Corp downstream affiliates (Proofpoint, 2026-06-18). This is the first Endgame phase to directly target the FakeUpdates component, an initial-access mechanism in continuous use since roughly 2017.

threat19 Jun 05:20Zmulti-sourceOpen finding ↗