Skip to content
Global Cyber Strike Disrupts SocGholish, Amadey, and StealC Malware Networks

Global Cyber Strike Disrupts SocGholish, Amadey, and StealC Malware Networks

Albaniandailynews June 24, 2026

Europol together with partners from across the globe today announces a landmark blow to cybercriminal networks as part of Operation Endgame, a sweeping international operation targeting the criminal infrastructure behind ransomware and malware like SocGholish, Amadey, and StealC. In coordinated actions over the past two weeks, key components of these malicious toolkits were dismantled as part of a public-private effort.

This included law enforcement from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, the US software company Microsoft and other private partners, with the international activity coordinated by Europol and Eurojust. The main common goal was to disrupt the "assembly lines" cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure.

Crypto assets of criminal origin currently valued at over EUR 41 million (USD 47 million) were identified, flagged, and thereby restricted from use. Moreover, as many as 27 million stolen login credentials have been recovered as part of this operation.

During this action, 326 servers and 142 domains were actioned by law enforcement and the private sector partners, severely crippling the malware’s distribution network. By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cybercriminals, making it harder for attacks to succeed, spread, or recover.

“Cybercrime-as-a-service” business model

The neutralised malware variants were offered as a service (“cybercrime-as-a-service”), with other cybercriminals using them as a tool for the initial infection of targeted systems. They subsequently served as a starting point for further criminal activities, such as installing ransomware for digital extortion or fraudulent use of data.

A blow to cybercriminal infrastructure

During the action against SocGholish, 14 971 infected websites - including those of restaurants, auto repair shops, and other everyday services - were remediated. SocGholish is linked to the Russian cyber?criminal group Evil Corp. This group has previously been responsible for Zeus and Dridex malware and is also associated with several large?scale ransomware and money?laundering operations.