Operation Endgame Disrupts StealC and Amadey Malware Networks

Operation Endgame Disrupts StealC and Amadey Malware Networks

4h ago Blogs.MicrosoftCyberscoopIbmwww.proofpoint.comFeeds2.Feedburner+10 82% similarity 71.0
Share:

Article Content

Browse articles
ThreatCluster

On June 24, 2026, Operation Endgame successfully disrupted the StealC and Amadey malware infrastructures, targeting 66 domains and 296 servers linked to these cybercrime tools. This operation, coordinated by Microsoft and various law enforcement agencies, aimed to dismantle the networks used for credential theft and ransomware deployment. The disruption resulted in the seizure of over 25.6 million stolen credentials and is expected to significantly impact the operations of both malware families. Amadey, a botnet known for distributing additional malware, and StealC, an infostealer, have been active since 2018 and 2023, respectively. The collaborative effort involved multiple private sector partners, including IBM X-Force and Proofpoint, highlighting the growing threat posed by malware-as-a-service models. The operation is anticipated to cause reputational and financial damage to the cybercriminals involved.

Key Points: • Operation Endgame disrupted 66 domains and 296 servers linked to StealC and Amadey. • Over 25.6 million stolen credentials were seized during the operation. • The disruption is expected to significantly impact the operations of both malware families.

ThreatCluster AI

Timeline

2026-06-24
Operation Endgame launched
Law enforcement and partners announced the disruption of StealC and Amadey malware networks, targeting 66 domains and 296 servers.
IBM
2026-06-24
Seizure of stolen credentials
Over 25.6 million stolen credentials were seized from compromised systems as part of the operation.
IBM
2026-06-24
Microsoft files lawsuit
Microsoft’s Digital Crimes Unit filed a lawsuit against multiple alleged enablers of StealC and Amadey.
Proofpoint
2026-06-24
Infrastructure dismantled
The operation dismantled key infrastructure enabling ransomware deployment and credential theft.
HelpNet Security

Community

Browse all →