A coordinated international law enforcement operation, supported by private sector partners including Bitdefender, Bitsight, ESET, and Microsoft, has successfully dismantled the criminal infrastructure behind the Amadey and StealC malware families. The action, conducted between June 15 and 19, 2026, as part of Operation Endgame, resulted in the recovery of 27 million stolen login credentials, the seizure of over $47 million in cryptocurrency assets, and the takedown of 326 servers and 142 domains.
Amadey, a C++-based modular backdoor active since October 2018, is sold under a malware-as-a-service (MaaS) model by the threat actor InCrease. It functions as a loader, distributing payloads such as Lumma Stealer, Vidar Stealer, StealC, Agent Tesla, and AsyncRAT. StealC, an information stealer first observed in January 2023, is sold by the threat actor plymouth and extracts credentials, session cookies, credit card data, and more from compromised systems. Both malware families employ checks to avoid infecting systems in Russia, Ukraine, Belarus, Kazakhstan, and Uzbekistan.
Microsoft identified over 18,000 victim computers and flagged 200 malicious C2 domains and IP addresses, which were shut down through court orders and domain seizures. The operation involved judicial and law enforcement authorities from Belgium, Canada, Denmark, France, Germany, the Netherlands, the U.K., and the U.S., coordinated by Europol and Eurojust. This marks a significant blow to the cybercrime-as-a-service ecosystem, targeting the initial access stage of attack chains.
CVEs: CVE-2026-11645
Attack groups: InCrease, plymouth, YouTubeTA
Malware: Amadey, StealC, SocGholish, Emmenhtal, SmokeLoader, Lumma Stealer, Vidar Stealer, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer
Companies: Bitdefender, Bitsight, ESET, Microsoft, Mitsui Bussan Secure Directions, CyberArk, IBM, Proofpoint
Events: Operation Endgame
Original source: thehackernews.com