Skip to content
Disrupting Cyberthreats Since 2008

Disrupting Cyberthreats Since 2008

www.microsoft.com June 24, 2026

Amadey and StealC are separate malwares developed by separate cybercriminals, but they relied on the same infrastructure and were operating in concert. Using AI tools like Copilot, DCU investigators were able to quickly uncover these hidden connections—building in minutes a picture that would have taken hours or days to assemble.

That insight allowed the legal team to treat both malware families as part of a single criminal conspiracy. Instead of going after each tool separately, as we have done in the past, we used RICO to charge anyone involved across the operation.

By targeting tools together, we can disrupt more of the cybercrime chain in a way that better reflects how these networks actually operate today. The goal is not just to stop one operation, but to slow the system itself—making attacks harder to launch, scale, and recover. By combining AI-driven insight, legal action, and strong partnerships, we can continue to raise the cost of cybercrime and reduce its impact.

Extracted Entities

Attack Types (1)

Malware (2)