International authorities and private security partners have disrupted infrastructure tied to the Amadey and StealC malware operations, expanding Operation Endgame’s campaign against the tools that help cybercriminals break into systems, steal data, and support follow-on attacks.
The coordinated action targeted servers, domains, and command-and-control systems associated with the two malware families. Europol said the operation disrupted 326 servers and 142 domains, identified more than 41 million euros, or about $47 million, in cryptocurrency linked to criminal activity, and recovered roughly 27 million stolen credentials from more than 385,000 compromised systems.
The action also reached SocGholish, also known as FakeUpdates, a malware loader commonly associated with compromised websites that push fake browser update prompts to visitors.
What Operation Endgame Targeted
Operation Endgame is aimed at the cybercrime services that sit near the beginning of many intrusion chains. These tools are not always the final payload in an attack. Instead, they can provide the access, stolen credentials, or foothold that other criminals use later for fraud, data theft, or ransomware attacks.
Amadey is commonly described as a loader used to establish access on infected devices and deliver additional malware. StealC is associated with credential and data theft, including information that can be valuable to criminals looking for account access or cryptocurrency wallets. Because these tools can feed other parts of the cybercrime market, disrupting them can create friction beyond a single malware campaign.
Microsoft’s Digital Crimes Unit said it had identified more than 200 malicious command-and-control domains and IP addresses associated with Amadey and StealC. The company said it worked with partners to limit that infrastructure through legal and technical actions, including court orders, domain seizures, registrations, and provider notifications. Those details are best understood as Microsoft-attributed claims rather than independently confirmed totals.
Microsoft also said the two malware families were linked to more than 140,000 infected devices during the first two weeks of May 2026. That figure gives a sense of the scale security teams are dealing with, even though botnet and malware infection counts can shift quickly as infrastructure changes and defenders intervene.
Why StealC and Amadey Matter
Malware such as Amadey and StealC often matters because of what it enables. A stolen password, browser session token, crypto wallet file, or system foothold can be sold, traded, or reused by a different actor later. That makes malware disruption less like shutting down one attack and more like interrupting part of a supply chain.
For defenders, the practical lesson is straightforward: credential theft and initial-access malware should be treated as serious network risk, not just isolated endpoint incidents. A single infected machine can expose accounts, browser data, and access paths that remain useful after the malware itself is removed.
Security teams should prioritize several checks after suspected exposure:
- Reset credentials associated with infected or potentially exposed systems.
- Review multi-factor authentication status for affected users and privileged accounts.
- Look for suspicious logins, new forwarding rules, unfamiliar OAuth grants, and unusual administrative activity.
- Inspect endpoints for secondary payloads, persistence mechanisms, and signs of lateral movement.
- Monitor for reused credentials appearing in unrelated systems after cleanup.
A Wider Push Against Malware Infrastructure
The disruption involved law enforcement agencies across North America and Europe, with Europol and Eurojust playing coordinating roles. A broader group of private security companies also contributed technical work, malware analysis, infrastructure mapping, or intelligence. Publicly named participants include Microsoft, ESET, Proofpoint, IBM X-Force, Bitsight, Infoblox, Orange Cyberdefense, Shadowserver, Have I Been Pwned, Spamhaus, and others, though the exact role and impact of each participant varies.
ESET said its work helped identify and disrupt infrastructure used by both malware families. The company put the affected footprint at roughly 50 domains and nearly 200 active command-and-control servers, a figure that should be read as ESET’s own assessment of its contribution to the operation.
Proofpoint, IBM X-Force, and Bitsight also described support for the action through intelligence, malware analysis, and infrastructure research. That kind of work is often critical in takedowns because command-and-control networks are rarely cleanly labeled. Investigators have to connect domains, hosting providers, IP addresses, malware samples, and operator behavior before legal or technical disruption is possible.
Disruption Does Not Mean Disappearance
Operation Endgame has previously focused on other malware families and cybercrime tools, including loaders, remote-access malware, and credential theft operations. The broader strategy is to make the criminal ecosystem more expensive and less reliable by removing infrastructure that many actors depend on.
That does not guarantee Amadey, StealC, or related operations are gone for good. Malware operators often attempt to rebuild after takedowns, especially when core developers or service operators remain outside law enforcement reach. Still, infrastructure disruption can slow campaigns, break existing infections’ communication paths, expose stolen data, and give defenders a window to clean up compromised systems.
For organizations, the most useful response is not to wait for a final victory lap. Treat the takedown as a prompt to search for indicators of compromise, rotate exposed credentials, harden endpoint controls, and verify that detection rules cover loaders and stealers as well as the ransomware payloads that may arrive later.
