Operation Endgame Disrupts Amadey and StealC Malware Networks

Operation Endgame Disrupts Amadey and StealC Malware Networks

7h ago Blogs.MicrosoftCyberscoopIbmwww.proofpoint.comFeeds2.Feedburner+12 82% similarity 72.2
Share:

Article Content

Browse articles
ThreatCluster

On June 24, 2026, Operation Endgame successfully disrupted the infrastructure of two major malware families, Amadey and StealC, used in cybercrime. This coordinated effort involved Microsoft, Europol, and various industry partners, targeting over 200 command-and-control servers and affecting approximately 140,000 infected computers globally. Amadey serves as a malware loader while StealC functions as an infostealer, both operating under a malware-as-a-service model. The operation resulted in the seizure of millions of stolen credentials and significant disruption to the cybercrime ecosystem. Microsoft utilized AI tools to uncover connections between the two malware families, allowing for a broader legal approach under the RICO Act. The disruption is expected to have a lasting impact on the operations of both malware families.

Key Points: • Operation Endgame disrupted over 200 command-and-control servers for Amadey and StealC. • Approximately 140,000 computers were identified as infected during the operation. • Microsoft leveraged AI tools to link the two malware operations for a coordinated legal response.

ThreatCluster AI

Timeline

2023-01-01
StealC launched as malware-as-a-service
StealC was introduced in January 2023, targeting sensitive information from compromised systems.
Article 2
2026-05-01
Over 140,000 infected computers linked to Amadey and StealC
In the first two weeks of May 2026, Microsoft identified over 140,000 infected devices globally.
Article 5
2026-06-24
Operation Endgame announced
The operation announced the disruption of Amadey and StealC, targeting their shared infrastructure.
Article 1
2026-06-24
Microsoft files lawsuit under RICO Act
Microsoft's Digital Crimes Unit filed a lawsuit against multiple alleged enablers of Amadey and StealC.
Article 7
2026-06-24
Disruption of 200+ C2 servers
The operation successfully disrupted over 200 command-and-control servers used by both malware families.
Article 10

Community

Browse all →