CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Amadey and StealC Malware Network Disrupted: 27 Million Stolen Credentials Recovered

June 25, 2026

A coordinated international law enforcement operation, supported by private sector partners including Bitdefender, Bitsight, ESET, and Microsoft, has successfully dismantled the criminal infrastructure behind the Amadey and StealC malware families. The action, conducted between June 15 and 19, 2026, as part of Operation Endgame, resulted in the recovery of 27 million stolen login credentials, the seizure of over $47 million in cryptocurrency assets, and the takedown of 326 servers and 142 domains.

Amadey, a C++-based modular backdoor active since October 2018, is sold under a malware-as-a-service (MaaS) model by the threat actor InCrease. It functions as a loader, distributing payloads such as Lumma Stealer, Vidar Stealer, StealC, Agent Tesla, and AsyncRAT. StealC, an information stealer first observed in January 2023, is sold by the threat actor plymouth and extracts credentials, session cookies, credit card data, and more from compromised systems. Both malware families employ checks to avoid infecting systems in Russia, Ukraine, Belarus, Kazakhstan, and Uzbekistan.

Microsoft identified over 18,000 victim computers and flagged 200 malicious C2 domains and IP addresses, which were shut down through court orders and domain seizures. The operation involved judicial and law enforcement authorities from Belgium, Canada, Denmark, France, Germany, the Netherlands, the U.K., and the U.S., coordinated by Europol and Eurojust. This marks a significant blow to the cybercrime-as-a-service ecosystem, targeting the initial access stage of attack chains.

CVEs: CVE-2026-11645

Attack groups: InCrease, plymouth, YouTubeTA

Malware: Amadey, StealC, SocGholish, Emmenhtal, SmokeLoader, Lumma Stealer, Vidar Stealer, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer

Companies: Bitdefender, Bitsight, ESET, Microsoft, Mitsui Bussan Secure Directions, CyberArk, IBM, Proofpoint

Events: Operation Endgame