NEWS
StealC Logs Kept Selling After the Endgame Server Raid
Operation Endgame seized Amadey and StealC servers in June 2026, yet StealC-labeled logs were still sold in August and no operators were named.
Operation Endgame’s June raid on Amadey and StealC recovered 27 million logins, yet StealC-labeled logs were still sold in August. Europol’s June 24, 2026 notice listed servers, domains, and frozen coins. It did not list an arrest.
Amadey is a loader that opens a foothold. StealC is a password stealer sold as a service. Buyers often chain them. The raid hit the shared shop. The goods already copied off those boxes, and the many small panels affiliates host themselves, were a different problem.
StealC Logs Were Still for Sale in August
Breachsense, which indexes stealer logs from private Telegram channels and criminal markets, published an August 2026 snapshot on September 8. The firm dated each record by when it indexed the file, not by when the PC was first infected, so the dump is a market tape, not a live map of new bots.
On that tape, StealC logs indexed in August still made up 24.1% of every credential that carried a family name. That was 10,781,277 StealC-labeled records from 139,414 machines, behind only the families tagged Meta and RedLine.
AUGUST 2026 LABELED STEALER LOGS
| Family | Credentials | Machines | Share of labeled set |
|---|---|---|---|
| Meta | 12,395,517 | 173,761 | 27.7% |
| RedLine | 11,467,129 | 202,154 | 25.6% |
| StealC | 10,781,277 | 139,414 | 24.1% |
| Vidar | 8,525,852 | 119,294 | 19.1% |
Only 44,728,743 of August’s 133,005,847 credential records named a family at all, about a third. The rest arrived unlabeled. Breachsense counted 1,217,555 infected machines on the month’s tape and 57,979,449 distinct username and password pairs. The typical box leaked 27 saved logins. A password reset on the one account that fired an alert leaves the other 26 in the log.
Taking command servers offline does not pull those files off Telegram. It also does not revoke the session cookies sitting next to the passwords. Anyone who ran StealC still has to treat saved logins, cookies, and crypto wallets on that PC as exposed, even if the panel they talked to is gone.
Europol Counted 326 Servers and 27 Million Logins
The action week ran from June 15 to 19, 2026. Europol and Eurojust coordinated police from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States. The same week also hit SocGholish, a fake-browser-update dropper tied to Evil Corp, which is why the headline totals mix three tools.
Europol said partners actioned 326 servers and 142 domains and recovered 27 million stolen login credentials. Crypto of criminal origin valued at over EUR 41 million ($47 million) was identified, flagged, and restricted from use. For SocGholish alone, 14,971 infected websites were cleaned, including restaurants and auto shops running WordPress.
Microsoft’s Digital Crimes Unit, working the Amadey and StealC slice, said those two tools were linked to more than 140,000 infected computers in the first two weeks of May 2026. Since the operation began, Microsoft said it identified more than 18,000 victim computers and severed criminal control of those devices. Those are three different piles: a May fortnight of infections, the boxes Microsoft could reach, and the logins sitting on seized servers.
WHO COUNTED THE JUNE RAID
| Who counted | What they counted | Servers or C2 | Domains | Credentials |
|---|---|---|---|---|
| Europol | SocGholish, Amadey, and StealC | 326 servers | 142 | 27 million recovered |
| IBM X-Force and Proofpoint | Amadey and StealC | 296 servers | 66 | 25.6 million unique |
| Microsoft DCU | Amadey and StealC C2 it actioned | over 200 C2 | domains and IPs together | not published |
| ESET | Amadey and StealC it had tracked | nearly 200 IP C2 | around 50 | not published |
IBM X-Force and Proofpoint, which built a StealC emulator for the case, said the Amadey and StealC portion yielded 25.6 million unique credentials stolen from over 385,000 compromised systems. That unique count sits inside Europol’s wider 27 million recovery, which also covers SocGholish. Victim alerts went out through Have I Been Pwned, Shadowserver, Spamhaus, DIVD, CheckjeHack, NoMoreLeaks, and the Dutch NCSC.
Microsoft Sued Two Malware Tools as One Plot
Amadey has been in the wild since at least 2018. StealC has been sold as malware-as-a-service since January 2023. Microsoft said separate crooks built them, then the tools kept landing on the same pipes. That overlap is what the civil case was for.
Steven Masada, assistant general counsel in Microsoft’s Digital Crimes Unit, said investigators used AI, including Copilot, to read the binaries in minutes instead of hours. The legal team then used the Racketeer Influenced and Corrupt Organizations Act, a U.S. statute written for organized crime, to treat both families as one conspiracy and go after multiple alleged enablers in a single unsealed case.
It’s no longer enough to go after threats one by one. We need to interrupt how the attacks are put together.
Steven Masada, Assistant General Counsel, Microsoft Digital Crimes Unit
That is a court tactic, not a police booking. The June 24 Europol notice names Canada’s RCMP, Denmark’s police, Germany’s BKA, the Dutch National High Tech Crime Unit, the UK’s National Crime Agency, and U.S. authorities. Private help came from Microsoft, Shadowserver, the Registrar of Last Resort, Proofpoint, IBM X-Force, Infoblox, NorthWave, Orange Cyberdefense, Bitdefender, Have I Been Pwned, and Spamhaus. ESET, BitSight, Lumen, and Japan’s Mitsui Bussan Secure Directions published their own tracking notes. None of those statements names a defendant in custody.
A Filename Bug Opened StealC’s Panels
StealC’s customers buy a Linux installer for a PHP control panel, then host that panel themselves. From it they build samples, watch infections, and push extra payloads. Version 2 shipped in March 2025. The build on the boxes in this raid was v2.22.0, released May 26, 2026, three weeks before the action week.
In early 2026, Proofpoint and IBM X-Force found a directory traversal bug in that panel. A stolen file’s name was not stripped of forward slashes. When the server unpacked a ZIP into /var/www/temp, it would write a web shell to a path of the attacker’s choosing. Police used that hole to search and seize StealC servers. StealC’s own developers patched it in February 2026. Investigators also found signs that one affiliate used the same bug to steal data from other affiliates.
The panel was, in the researchers’ words, iteratively stitched onto older stealer code. Affiliates had already been complaining on underground forums about other bugs. A shop that cannot keep its own customers from robbing each other is not a fortress. It is still a shop, and shops get rebuilt.
WHAT STEALC PULLED FROM A BOX
- Browsers: Passwords, cookies, history, autofill, tokens, credit cards, and extension data.
- Chat and mail: Thunderbird, Outlook, Foxmail, Telegram, Discord, and Tox.
- Wallets and remote access: Crypto wallets plus Azure, OpenVPN, ProtonVPN, FileZilla, and WinSCP.
- Games: Steam, Battle.net, and Uplay, with extra file rules the buyer could add.
The emulator also watched what StealC loaded next. Payloads included Amadey, AsyncRAT, HijackLoader, RedLine, SmokeLoader, Vidar, XMRig, and, in one chain, XTinyLoader dropping LockBit Black. A ransomware payload was the exception in that sample set. The usual job was to turn one infected Windows box into a pile of logins and a door for the next tool.
73 StealC Clusters Shared No Kill Switch
ESET had been tracking both families for three years and handed over statistics covering the fourth quarter of 2025 through the first half of 2026, plus encryption keys, campaign IDs, and known command servers. Researcher Jakub Tomanek said that package went into the disruption.
On Amadey, ESET mapped 53 unique clusters. Affiliates paid for a license, then paid again each time they needed a new build, for example when they rotated to a new command server. RC4 keys stayed with the affiliate across rebuilds, which made them a useful tag. One cluster accounted for almost 34 percent of the Amadey samples ESET processed, and it was the only cluster that stayed active for the whole window.
StealC was more broken up. ESET identified 73 distinct StealC clusters operating since March 2025. Each cluster sat on a small number of command servers, often just one, tied to a few build IDs or URL paths. “Disrupting such infrastructure is therefore a challenging task due to the lack of a weak point,” the firm wrote. Around 50 domains and nearly 200 active IP-based command servers in ESET’s set were hit.
That geometry is why a 326-server headline and an August log tape can both be true. There was never one Amadey brain or one StealC brain. There were dozens of rented panels. Knock down the ones you can see, and the buyers who already have a copy of the builder still have a product to sell.
Secret Blizzard Rode the Same Cheap Loader
Most of the targeting was indiscriminate. ESET’s detections put Amadey heaviest in India, Turkey, Egypt, Mexico, and Spain, and StealC heaviest in the United States, Poland, and Italy. The point of the business is volume: infect first, sell the access or the passwords later.
Microsoft has also watched a Russian-affiliated actor it calls Secret Blizzard, the group widely tracked as Turla, lean on Amadey infections to drop custom malware against targets in Ukraine. A loader you can rent on a forum is useful to a low-level cash crew and to a spy team that wants to look like a low-level cash crew. The same class of phishing that puts Amadey on a home PC can put it on a box that matters to a government.
SocGholish in the same action week showed how wide that net is. Fake update pop-ups on hacked WordPress sites, including restaurants and repair shops, were the front door. Europol’s own write-up of the loader-and-stealer pipeline is that Amadey opens the door and StealC empties the browser. Secret Blizzard did not need a boutique implant to take the first step. It needed a commodity loader that other people were already spreading.
Endgame Has Come Back for Customers Before
Operation Endgame is the banner Europol has used since May 2024 for raids on the tools that feed ransomware. The June 2026 week was another pass at that middle layer, not at a named gang’s headquarters. Dutch police even billed the Amadey and StealC hits as infostealers “taken down again.”
ENDGAME PHASES BEFORE AMADEY
- May 27 to 29, 2024: Police hit droppers including IcedID, SystemBC, Pikabot, SmokeLoader, Bumblebee, and Trickbot, with 4 arrests, 16 location searches, and more than 100 servers taken down.
- April 2025: Investigators used a SmokeLoader customer database seized in 2024 to identify buyers of a pay-per-install service run under the alias Superstar, then ran arrests, searches, and knock-and-talks against those customers.
- November 3, 2025: The main suspect for VenomRAT is arrested in Greece.
- November 10 to 13, 2025: Endgame targets Rhadamanthys, VenomRAT, and the Elysium botnet, with 1,025 servers taken down or disrupted, 20 domains seized, and 11 locations searched.
- June 15 to 19, 2026: SocGholish, Amadey, and StealC infrastructure is actioned. Europol lists 326 servers, 142 domains, 27 million recovered logins, and EUR 41 million in flagged crypto, and does not list an arrest.
The 2024 SmokeLoader sequel is the pattern worth keeping in view. Endgame’s first cut took servers. Months later the same files turned into names. Amadey and StealC affiliates, by design, stood up their own panels and paid per rebuild. That leaves a customer list, if the seized servers held one, as the part of this raid that has not yet been spent.
Until that happens, the June scoreboard and the August tape describe two halves of one market. Police and Microsoft cut the pipes they could reach. The logs those pipes had already produced were still being sold, 73 StealC clusters never shared a single switch, and the people who rented the tools were not on the press release.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
