Operation Endgame Disrupts Amadey and StealC Malware Networks
ID: 8208e691-9e55-5403-b50a-6184c8448173
STIX ID: report--8208e691-9e55-5403-b50a-6184c8448173
Feed Name: ThreatCluster
On June 24, 2026, Operation Endgame — involving Microsoft, Europol, and industry partners — disrupted the infrastructure of the Amadey loader and StealC infostealer by seizing over 200 command-and-control servers, recovering millions of stolen credentials, and identifying roughly 140,000 infected systems worldwide; Microsoft leveraged AI to link the two malware families and pursue a broader legal strategy under the RICO Act, with the disruption expected to substantially impact the malware-as-a-service operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
