ctipilot.ch

Operation Endgame — Amadey/StealC takedown

campaign · campaign:operation-endgame-amadey-stealc single-source

Operation Endgame law-enforcement action dismantling the Amadey and StealC malware-as-a-service infrastructure.

Coverage timeline
6
first 2026-06-19 → last 2026-06-29
Peak priority
high
2 high · 4 notable
Sources cited
12
11 hosts
Sections touched
4
active-threats, weekly-incidents-recap, weekly-long-running
Co-occurring entities
1
see Related entities below
ATT&CK techniques
3
pinned v19.1 · see below
2026-06-196 appearances2026-06-29

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

Story timeline

  1. 2026-06-29Operation Endgame
    weekly-long-running
  2. 2026-06-25Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
    active-threats
  3. 2026-06-22SocGholish / TA569 — Operation Endgame seized 106 servers, but seven delivery clusters remain operational
    weekly-long-running
  4. 2026-06-22Research: ClickFix matured into a productised malware-as-a-service supply chain
    weekly-research
  5. 2026-06-22Law-enforcement momentum — Operation Endgame expands, Silver Fox mass-arrest, Conti loader plea
    weekly-incidents-recap
  6. 2026-06-19Operation Endgame expands to SocGholish/TA569 — 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites
    active-threats

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

includes

Where this entity is cited

  • active-threats2
  • weekly-long-running2
  • weekly-incidents-recap1
  • weekly-research1

Source distribution

  • proofpoint.com2 (17%)
  • bleepingcomputer.com1 (8%)
  • blog.sekoia.io1 (8%)
  • europol.europa.eu1 (8%)
  • globalsecurity.org1 (8%)
  • helpnetsecurity.com1 (8%)
  • huntress.com1 (8%)
  • microsoft.com1 (8%)
  • other3 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (12)

Entries about Operation Endgame — Amadey/StealC takedown (6)

2026-06-29 · view entry permalink →

NOTABLE

Operation Endgame

Europol's law-enforcement campaign extended its reach this week: the 06-24/25 Amadey and StealC takedown actioned 326 servers and 142 domains and recovered approximately 27 million stolen credentials from over 385,000 compromised systems (BleepingComputer), with Microsoft providing the Amadey/StealC infrastructure analysis (Microsoft). Combined with the W25 SocGholish/TA569 seizure (106 servers), Endgame has now dismantled three commodity delivery-and-theft networks in quick succession. The defender gap: no arrests were announced for this phase, so infrastructure can reconstitute — cross-reference the recovered 27M credentials against your identity-store canaries and hunt Amadey persistence (HKCU run-key, rundll32/regsvr32 side-loads, short-lived child processes under %AppData%\Roaming).

synthesis29 Jun 00:21Zmulti-sourceOpen finding ↗

2026-06-25 · view entry permalink →

HIGH

Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone

A Europol-coordinated law-enforcement and private-sector action on 24 June 2026 took down the shared infrastructure of Amadey and StealC — two of the dominant commodity malware-as-a-service families that form the pre-ransomware infection chain (Microsoft, 2026-06-24 · Europol, 2026-06-24). 326 servers and 142 domains were seized, ~27 million credentials stolen from 385,000+ systems recovered, and EUR 41M in crypto frozen (BleepingComputer, 2026-06-24). Amadey (active since 2018) is a modular C++ loader with 29+ commands, scheduled-task persistence and payload staging; StealC is a C++ infostealer-MaaS harvesting browser credentials, cookies, wallets and desktop clients over RC4-encrypted HTTP. ESET contributed RC4 keys and clustering that identified 53 Amadey and 73 StealC clusters (ESET, 2026-06-24); Proofpoint and IBM X-Force documented a directory-traversal flaw in StealC's C2 panel (its filename sanitiser failed to strip forward-slashes), and an exploit built on it was used by global law enforcement to map and access affiliate infrastructure (Proofpoint/IBM X-Force, 2026-06-24). This is a distinct action from the SocGholish/TA569 phase covered on 2026-06-19. Why it matters to us: Detecting Amadey delivery (ClickFix fake-CAPTCHA, SEO poisoning) and StealC exfiltration is a real ransomware pre-emption opportunity. Hunt scheduled-task creation (EID 4698) by browser/Office parents from %APPDATA% paths, and browser-process → mshta.exe/wscript.exe chains with temp-path arguments.

326 servers and 142 domains while identifying €41 million in cryptocurrency tied to criminal activity. Investigators recovered approximately 27 million credentials stolen from over 385,000 compromised systems

BleepingComputer

Amadey has been active in the crimeware ecosystem since 2018 and functions as a modular backdoor with access to more than 29 backdoor commands and a wide variety of plugins

Microsoft Threat Intelligence
threat25 Jun 04:59Zmulti-sourceOpen finding ↗

2026-06-22 · view entry permalink →

NOTABLE

SocGholish / TA569 — Operation Endgame seized 106 servers, but seven delivery clusters remain operational

key: item:operation-endgame-expands-to-socgholish-ta569-106-c2-servers. The Operation Endgame takedown (§ 5) was the headline; Proofpoint's post-action analysis is the status update that matters for the longer arc. TA569 served for years as a primary distribution layer for WastedLocker (Evil Corp), LockBit and RansomHub, and while law enforcement seized over 100 servers and 14,971 WordPress sites were remediated, seven FakeUpdates-style clusters remain operational — TA2726, TA2727, ZPHP, ErrTraffic (the ClickFix MaaS in § 6), LandUpdate808/KongTuke, GeoTDS and tdsshop (Proofpoint, 2026-06-18; daily 06-19). Proofpoint also notes WordPress sites frequently reinfect because the underlying credential compromise outlives CMS-level cleanup. The defender consequence: the fake-update initial-access vector is degraded, not closed — keep GPO restrictions on JScript/WSH execution from user-writable paths, browser isolation for email links, and (for WordPress operators) full credential rotation plus FIM after any cleanup, because removing the loader without rotating credentials invites reinfection.

synthesis22 Jun 00:15Zsingle-sourceOpen finding ↗
Sources: Proofpoint

Earlier coverage (3)