Threats · 80 days ago
The break is no longer just which machines were infected. Law enforcement is now dismantling the servers and domains that let Amadey and StealerC mass-deploy credential theft, so the crews lose the machinery that turns one infection into a repeatable business.
Shadowserver says partners recovered almost 30 million compromised credentials stolen by StealC between 4 July 2025 and 16 June 2026. The latest Operation Endgame action also targeted Amadey and StealerC infrastructure, after the earlier phase went public with SocGholish disruption and broader takedowns across 326 servers and 142 domains.
That gives defenders more than a leak to review. It can expose older Windows compromises and credential reuse across incidents, and that retrospective value persists even after the distribution layer is disrupted.
13 sources covering this story
Risky Bulletin: Operation Endgame dismantles Amadey and StealerC
Law enforcement dismantles two more malware operations, Japan's army used infected USB drives, Anthropic accuses Alibaba of distillation a [Read More
StealC Historical Bot Infection Special Report
This time the StealC infostealer and Amadey malware-as-a-service families were targeted.
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
Law enforcement dismantled 326 servers and 142 domains tied to Amadey and StealC, recovering 27 million stolen credentials.
One-two punch delivered in global operation disrupts cybercrime "assembly line"
Operation Endgame" simultaneously disrupts two widely used crime tools.
The Record from Recorded Future
Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement
Microsoft touted its latest action against malware infrastructure as a new approach aimed at the full cybercrime "supply chain." Europol said more than 300 servers were targeted.
Operation Endgame Takes Down StealC and Amadey Infostealers
Operation Endgame seized around 50 domains and nearly 200 active IP-based servers associated with the infostealers
Law enforcement hits StealC and Amadey malware networks - Help Net Security
As part of Operation Endgame, aw enforcement and private sector partners disrupted the infrastructure delivering StealC and Amadey malware.
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights.
In a first, a court takedown goes after two cybercrime tools at once
Microsoft and global law enforcement joined forces to simultaneously disrupt the Amadey and StealC malware operations using AI insights and the RICO Act.
This blog is a technical breakdown of StealC and Amadey.
Microsoft, Europol lead global takedown of infostealer malware
Cybercriminals used Amadey and StealC to infect thousands of computers worldwide, leading to ransomware and other digital crimes.
Part of the PlainSec briefing for 2026-06-27