Tech

Operation Endgame disrupts cybercrime assembly line targeting Amadey and StealC

A coordinated global operation has seized over 200 command-and-control servers, recovered 27 million stolen credentials, and identified $47 million in criminal crypto assets linked to the Amadey and StealC platforms.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · original
One-two punch delivered in global operation disrupts cybercrime "assembly line"
International authorities and Microsoft dismantle overlapping infrastructure used for credential theft and ransomware

International law enforcement agencies and private technology firms, led by Microsoft and Europol, have executed a coordinated takedown of two major cybercrime platforms, Amadey and StealC. The operation, designated as Operation Endgame, targeted the overlapping infrastructure that allowed these distinct tools to function as a unified cybercrime “assembly line.” The disruption resulted in the seizure of more than 200 command-and-control servers and severed criminal control over over 18,000 infected computers.

Microsoft utilised artificial intelligence to identify that Amadey, a malware-as-a-service platform active since 2018, and StealC, an infostealer-as-a-service, relied on shared underlying infrastructure despite being run independently. This technical insight enabled Microsoft attorneys to invoke RICO statutes, treating the two tools as part of a single conspiracy. This legal strategy allowed for simultaneous action against both platforms, which are frequently used together by attackers to gain device access and subsequently steal sensitive data.

Europol reported the recovery of up to 27 million stolen login credentials and the identification of $47 million in crypto assets of criminal origin. The agency actioned 326 servers and 142 domains, significantly crippling the distribution networks for the malware. Europol noted that the simultaneous disruption increases friction for cybercriminals, making it more difficult for attacks to succeed, spread, or recover from the takedown.

The operation also targeted SocGholish, a malware loader linked to the Evil Corp group that spreads through compromised websites by tricking visitors into installing trojanised applications. Europol has cleaned infected WordPress sites and urged administrators to change credentials and tighten security. The agency is also working to notify parties whose data and credentials were exposed through SocGholish activities.

Participating nations in the enforcement action included Canada, Denmark, Germany, the Netherlands, the UK, and the US. Other technology companies assisting in the operation included ESET, Proofpoint, IBM X-Force, Bitsight, and Mitsui Bussan Secure Directions. The collaboration highlights the growing role of public-private partnerships in dismantling complex digital criminal ecosystems.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon