---
schema: 1
kind: threat
title: Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
headline: Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
summary: "Operation Endgame dismantles Amadey and StealC MaaS infrastructure — a Europol-coordinated action on 24 June took down 326 servers and 142 domains, recovered ~27 million stolen credentials from 385,000+ systems and froze EUR 41M (BleepingComputer, 2026-06-24); both families are commodity initial-access and credential-theft stages that feed ransomware affiliates active against European targets (Microsoft, 2026-06-24)."
discovered_at: "2026-06-25T04:59:05Z"
event_date: 2026-06-24
run_id: 2026-06-25-da7fbd23
priority: high
immediate_action: null
tags:
  - law-enforcement
  - infostealer
  - botnet
  - organized-crime
  - ransomware
regions:
  - europe
  - global
sectors:
  - public-sector
  - finance
entities:
  - "campaign:operation-endgame-amadey-stealc"
cves: []
sources:
  - url: "https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/"
    publisher: Microsoft Threat Intelligence
    role: primary
  - url: "https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks"
    publisher: Europol newsroom
    role: corroborating
  - url: "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
    publisher: ESET WeLiveSecurity
    role: corroborating
  - url: "https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame"
    publisher: Proofpoint / IBM X-Force
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/"
    publisher: BleepingComputer
    role: corroborating
closed_sources: []
evidence:
  - quote: "326 servers and 142 domains while identifying €41 million in cryptocurrency tied to criminal activity. Investigators recovered approximately 27 million credentials stolen from over 385,000 compromised systems"
    publisher: BleepingComputer
  - quote: Amadey has been active in the crimeware ecosystem since 2018 and functions as a modular backdoor with access to more than 29 backdoor commands and a wide variety of plugins
    publisher: Microsoft Threat Intelligence
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-25.md
---

A Europol-coordinated law-enforcement and private-sector action on 24 June 2026 took down the shared infrastructure of Amadey and StealC — two of the dominant commodity malware-as-a-service families that form the pre-ransomware infection chain ([Microsoft, 2026-06-24](https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/) · [Europol, 2026-06-24](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks)). 326 servers and 142 domains were seized, ~27 million credentials stolen from 385,000+ systems recovered, and EUR 41M in crypto frozen ([BleepingComputer, 2026-06-24](https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/)). Amadey (active since 2018) is a modular C++ loader with 29+ commands, scheduled-task persistence and payload staging; StealC is a C++ infostealer-MaaS harvesting browser credentials, cookies, wallets and desktop clients over RC4-encrypted HTTP. ESET contributed RC4 keys and clustering that identified 53 Amadey and 73 StealC clusters ([ESET, 2026-06-24](https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/)); Proofpoint and IBM X-Force documented a directory-traversal flaw in StealC's C2 panel (its filename sanitiser failed to strip forward-slashes), and an exploit built on it was used by global law enforcement to map and access affiliate infrastructure ([Proofpoint/IBM X-Force, 2026-06-24](https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame)). This is a distinct action from the SocGholish/TA569 phase covered on 2026-06-19.
**Why it matters to us:** Detecting Amadey delivery (ClickFix fake-CAPTCHA, SEO poisoning) and StealC exfiltration is a real ransomware pre-emption opportunity. Hunt scheduled-task creation (EID 4698) by browser/Office parents from `%APPDATA%` paths, and browser-process → `mshta.exe`/`wscript.exe` chains with temp-path arguments.
