NEWS
Operation Endgame Severs Amadey and StealC Malware Pipeline
Europol and Microsoft led a sweep that dismantled 326 servers and 142 domains tied to the Amadey loader and StealC infostealer between June 15 and 19, 2026.
The Amadey loader and StealC infostealer powered a commodity pipeline that gave a Russian state-aligned hacking crew an entry point inside Ukrainian military devices. Both halves of that pipeline lost their infrastructure in a coordinated Europol-Microsoft sweep that ran June 15 to 19, 2026. Operation Endgame, announced June 24, is the largest international operation ever undertaken to tackle ransomware enablers worldwide.
Law enforcement from seven agencies across six countries worked with Microsoft and more than ten private security partners to dismantle 326 servers and 142 domains powering the Amadey loader and the StealC infostealer. The action restricted crypto assets of criminal origin valued at over $47 million and reclaimed 27 million stolen credentials that had been sitting in criminal hands. Europol framed the operation as a strike on the assembly line cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure. The agency said the takedown is part of Operation Endgame, the largest international operation ever undertaken to tackle ransomware enablers.
The Two-Week Sweep
The synchronized takedown ran between June 15 and 19. Microsoft’s Digital Crimes Unit identified more than 200 malicious command-and-control domains and IP addresses and moved to shut them down through court orders, domain seizures, registrations, and provider notifications. Microsoft’s researchers used AI tools, including Copilot, to analyze the binaries and identify command-and-control servers hardcoded into them.
The public-private coordination spanned at least eleven named private-sector participants beyond Microsoft, including the Shadowserver Foundation, Proofpoint, IBM X-Force, Infoblox, Bitdefender, NorthWave, Orange Cyberdefense, Have I Been Pwned, Spamhaus, and the Registrar of Last Resort. Bitsight’s technical writeup describes the firm’s contribution as command-and-control infrastructure mapping, indicators of compromise, and real-time infection telemetry drawn from running sinkholing operations against both malware families. ESET and Bitdefender researchers also published detailed analyses of the affiliate models each tool uses. Microsoft framed the operation as a new strategy targeting the cybercrime supply chain.
- Canada: Royal Canadian Mounted Police (RCMP)
- Denmark: Danish Police (Politi)
- Germany: Federal Criminal Police Office (BKA)
- Netherlands: National High Tech Crime Unit (NHCTU)
- United Kingdom: National Crime Agency (NCA)
- United States
- Europol and Eurojust
The company said the joint action increases friction for criminals trying to rebuild. One of the participating security firms went further, framing the action as a warning shot to the malware underground. Bitsight and Microsoft had both been tracking the botnets through sinkholing operations for months before the action came together, per their respective writeups.
This takedown is a powerful demonstration of what public and private sector collaboration can achieve in dismantling the infrastructure that enables cybercrime at scale. It also sends a clear message to those behind malware ecosystems: no matter how sophisticated the tools or how distributed the network, coordinated international action will find them.
Alex Cosoi, Bitdefender’s chief security strategist, said it in a statement released the same day. His firm was one of the eleven private-sector partners named by Europol.
One Pipeline, Two Halves
Amadey and StealC form a single commodity chain that Microsoft’s researchers linked to more than 140,000 infected computers worldwide in just the first two weeks of May 2026. Amadey is the loader, a piece of rented-out malware designed to break in first, fingerprint the host, and call home for instructions. StealC is the stealer that follows once the loader has cleared the path.
StealC harvests credentials, cookies, crypto wallets, and session tokens from infected machines. Amadey has been sold on Russian-language underground forums since 2018 by an actor using the handle “InCrease.” Buyers get a modular loader that doubles as a remote-access trojan, capable of taking screenshots, opening VNC sessions, spawning SOCKS proxies, and pulling in additional payloads on demand. StealC, a C++ infostealer that surfaced in early 2023, goes further: it exfiltrates data from dozens of browsers, more than 100 wallet and authenticator browser extensions, and desktop apps like Discord, FileZilla, Outlook, and Telegram, per how StealC and Amadey operate as a chain.
| Attribute | Amadey | StealC |
|---|---|---|
| Role | Modular loader and remote-access trojan | Infostealer with loader capability |
| Active since | 2018 | early 2023 |
| Sold by | Threat actor “InCrease” on Russian forums | Threat actor “plymouth” on xss[.]is and exploit[.]in |
| Pricing model | $600 one-time license plus $50 per rebuild | $280 to $880 subscription for 1 to 6 months |
| Self-kill locale | Russian, Ukrainian, and Belarusian hosts | Russian, Ukrainian, Belarusian, Kazakh, and Uzbek hosts |
| Latest version | 5.87 | 2.2.1 |
Both tools check the system locale before executing their most invasive functions, and both refuse to act on hosts set to Russian, Ukrainian, or Belarusian languages. StealC is more aggressive about it, also refusing to run on Kazakh and Uzbek hosts, a pattern researchers say is meant to keep the operators out of local law-enforcement reach.
The chain works because both halves are sold to overlapping customer bases. Threat actors buy Amadey to break in, then either deploy StealC themselves or rent StealC access from a different operator. Microsoft’s researchers, working with Bitsight telemetry, found that Amadey and StealC frequently reused the same command-and-control infrastructure, with StealC running as one of many payloads Amadey dropped onto the same machine.
Microsoft’s research counted 53 unique clusters inside the Amadey family at various points, with the largest distributing payloads including Lumma Stealer, Vidar Stealer, StealC, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer, SmokeLoader, XWorm, and AsyncRAT. Per Microsoft, access brokers then validate and resell stolen credentials at a premium to threat actors seeking footholds into enterprise networks.
The Russian APT That Rode the Same Tracks
In December 2024, Microsoft published research showing Russia’s Foreign Intelligence Service-linked group Secret Blizzard, also tracked as Turla, used the Amadey botnet to deliver its own backdoors to Ukrainian military devices. The activity ran between March and April 2024, with the FSB-affiliated crew commandeering or renting access to Amadey infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency has attributed Secret Blizzard to Center 16 of Russia’s Federal Security Service, per Secret Blizzard’s use of Amadey against Ukraine.
Microsoft assessed that Secret Blizzard either purchased Amadey as a service or quietly accessed its command-and-control panels to drop a PowerShell loader that pulled the Russian tooling down. The Amadey instance used in those intrusions was version 4.18, which carried the same fingerprinting and persistence features as the rest of the botnet.
The Tavdig backdoor was loaded through a legitimate Symantec binary susceptible to DLL sideloading, and it set the stage for KazuarV2, a second-stage implant Microsoft has tied to Secret Blizzard in multiple campaigns. Devices were subsequently used to harvest Microsoft Defender logs, system directory trees, SMB shares, and active sessions, and to relay command output through compromised web servers running the group’s relay module. Microsoft assessed that Secret Blizzard’s survey tool was selectively deployed to devices of further interest, including those egressing from Starlink IP addresses. The December 2024 report marks the second time since 2022 that Microsoft has seen Secret Blizzard ride a cybercrime campaign as a foothold for its own espionage tooling.
The same rental marketplace that hands a credential stealer to a low-level affiliate also gave a Russian intelligence service a low-cost path into Ukrainian military endpoints. State-aligned use of criminal infrastructure has shown up elsewhere, as in Iran’s ministry posing as a Chaos ransomware brand, and the sweep raises the cost of that playbook for everyone who used it. Microsoft researchers said Secret Blizzard has long relied on commandeering access from cybercriminal crews.
What $600 Bought on the Russian Forums
The Amadey-SteaC pair sold cheaply. Bitsight documented the Amadey listing as a $600 one-time license plus a small rebuild fee, stable for years and advertised on Russian forums under the InCrease handle. StealC’s operator “plymouth” priced subscriptions at $280 to $880 for one to six months on xss[.]is and exploit[.]in. Both listings sat in the same commodity tier as RedLine, Lumma, Vidar, and Raccoon, the everyday infostealers of the underground.
In April 2025, “plymouth” put the older StealC v1.12.2 source code up for sale for $3,000, capped at five buyers, and it sold out within two weeks. That kind of source-code dump is the usual precursor to forks and copycats showing up downstream. Bitsight’s researchers say StealC split into two lineages in March 2025: the original v1 and a v2 rewrite with full server-side decryption of Chromium and Firefox data.
The two tools also sold under different affiliate philosophies. ESET researchers Jakub Tomanek and Tomáš Procházka wrote that Amadey used a pay-per-rebuild model, where affiliates paid a fee every time they needed a new build to rotate to a fresh command-and-control server. StealC took a different affiliate approach, offering unlimited build generation as part of the subscription. Bitsight’s writeup details how the C2 infrastructure mapping that supported the action gave investigators visibility into both affiliate bases, per the C2 infrastructure mapping that supported the action.
What the Takedown Did Not Catch
The numbers in the takedown stack up fast. Investigators flagged 326 servers and 142 domains, restricted crypto valued at over $47 million, reclaimed 27 million credentials, and severed criminal control of 18,000 victim computers Microsoft had identified. The first two weeks of May 2026 alone saw more than 140,000 devices linked to the Amadey-SteaC pair worldwide.
No arrests were announced in the Europol statement, the Bitsight writeup, or Microsoft’s blog post, and the handles InCrease and plymouth remained unattached to any individual. The MaaS model is also built to recover: subscriptions stay active, source code circulates, and the stealer market has consolidated as competing tools have been disrupted. Europol described Operation Endgame as the largest international operation ever undertaken to tackle ransomware enablers, and the agency said further actions against the same networks are planned. The MaaS operators behind the InCrease and plymouth handles remain unnamed.
-
AI4 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
