Minacce · 95 giorni fa
La storia è passata dalla pubblicazione dei compromessi allo smontaggio delle linee di produzione che li rendono scalabili. Togliere di mezzo i server e i domini usati da Amadey e StealerC significa colpire la capacità operativa dei gruppi, non solo esporre ciò che avevano già rubato: senza quella base, il furto di credenziali perde la macchina che lo distribuisce su massa.
Nell’azione coordinata del 15-19 giugno, law enforcement e partner privati hanno agito su 326 server e 142 domini legati a più infrastrutture criminali, tra cui SocGholish, Amadey e StealerC. Sono stati recuperati quasi 30 milioni di credenziali rubate da StealerC tra il 4 luglio 2025 e il 16 giugno 2026, e Shadowserver sta distribuendo parte di quel materiale per aiutare a bonificare host Windows storici e recenti.
Per i team che inseguono il solo malware familiare, il punto cambia: il blocco della distribuzione può far emergere credenziali di vecchie infezioni e riaprire compromessi che sembravano chiusi. Dove c’è riuso di password o una base di endpoint Windows ampia, il dato recuperato diventa intelligence retrospettiva, non semplice residuo di un sequestro.
13 fonti che coprono questa storia
Risky Bulletin: Operation Endgame dismantles Amadey and StealerC
Law enforcement dismantles two more malware operations, Japan's army used infected USB drives, Anthropic accuses Alibaba of distillation a [Read More
StealC Historical Bot Infection Special Report
This time the StealC infostealer and Amadey malware-as-a-service families were targeted.
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
Law enforcement dismantled 326 servers and 142 domains tied to Amadey and StealC, recovering 27 million stolen credentials.
One-two punch delivered in global operation disrupts cybercrime "assembly line"
Operation Endgame" simultaneously disrupts two widely used crime tools.
The Record from Recorded Future
Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement
Microsoft touted its latest action against malware infrastructure as a new approach aimed at the full cybercrime "supply chain." Europol said more than 300 servers were targeted.
Operation Endgame Takes Down StealC and Amadey Infostealers
Operation Endgame seized around 50 domains and nearly 200 active IP-based servers associated with the infostealers
Law enforcement hits StealC and Amadey malware networks - Help Net Security
As part of Operation Endgame, aw enforcement and private sector partners disrupted the infrastructure delivering StealC and Amadey malware.
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights.
In a first, a court takedown goes after two cybercrime tools at once
Microsoft and global law enforcement joined forces to simultaneously disrupt the Amadey and StealC malware operations using AI insights and the RICO Act.
This blog is a technical breakdown of StealC and Amadey.
Microsoft, Europol lead global takedown of infostealer malware
Cybercriminals used Amadey and StealC to infect thousands of computers worldwide, leading to ransomware and other digital crimes.
Part of the PlainSec briefing for 2026-06-27