Criminal Malware Assembly Lines Are Being Torn Down

The break is no longer just which machines were infected. Law enforcement is now dismantling the servers and domains that let Amadey and StealerC mass-deploy credential theft, so the crews lose the machinery that turns one infection into a repeatable business. Shadowserver says partners recovered almost 30 million compromised credentials stolen by StealC between 4 July 2025 and 16 June 2026. The latest Operation Endgame action also targeted Amadey and StealerC infrastructure, after the earlier phase went public with SocGholish disruption and broader takedowns across 326 servers and 142 domains. That gives defenders more than a leak to review. It can expose older Windows compromises and credential reuse across incidents, and that retrospective value persists even after the distribution layer is disrupted.

Part of the PlainSec briefing for 2026-06-27

Sources