logo

ESET takes part in Operation Endgame to disrupt Amadey and Stealc

ID: 8bfc5afa-0856-5c5a-8f5f-9273c0cbc7e8

STIX ID: report--8bfc5afa-0856-5c5a-8f5f-9273c0cbc7e8

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2026-06-24

Date Updated: 2026-06-25

...
...

ESET participated in Operation Endgame to disrupt two malware-as-a-service families—Amadey (loader) and Stealc (infostealer)—by contributing long-term telemetry, technical analysis, RC4 keys, build and campaign identifiers, and C2 lists; the operation impacted roughly 50 domains and nearly 200 active C2 IPs, and the report details both families’ architectures, C2 protocols, clustering methodology (53 Amadey clusters, 73 Stealc clusters), representative IoCs, and MITRE ATT&CK mappings to support detection and future monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.