logo

Operation Endgame Disrupts Amadey and StealC Malware Networks

ID: 8208e691-9e55-5403-b50a-6184c8448173

STIX ID: report--8208e691-9e55-5403-b50a-6184c8448173

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-24

Date Updated: 2026-06-25

...
...

On June 24, 2026, Operation Endgame — involving Microsoft, Europol, and industry partners — disrupted the infrastructure of the Amadey loader and StealC infostealer by seizing over 200 command-and-control servers, recovering millions of stolen credentials, and identifying roughly 140,000 infected systems worldwide; Microsoft leveraged AI to link the two malware families and pursue a broader legal strategy under the RICO Act, with the disruption expected to substantially impact the malware-as-a-service operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.