Latest
Cybercrime

Operation Endgame Dismantles Amadey and StealC and Recovers 27 Million Credentials

Operation Endgame Dismantles Amadey and StealC and Recovers 27 Million Credentials

On Monday, Europol announced that the global law enforcement community, working together with several key private-sector organizations, including Bitdefender, Bitsight, ESET, and Microsoft, successfully conducted a major operation against organized crime groups responsible for developing and maintaining malware ecosystems, specifically the Amadey and StealC platforms.

Europol described the efforts as follows: "The main common goal was to disrupt the 'assembly lines' that cyber criminals use to launch ransomware attacks, commit financial fraud, and compromise critical infrastructure."

This announcement came just days after Europol announced that authorities from Canada, Germany, the Netherlands, and the United States worked together to take down a large portion of the SocGholish (also referred to as SocGhiolish) malware ecosystem. That effort included cleaning up approximately 14,900 infected WordPress websites.

During the two-week joint law enforcement and private industry effort, authorities identified and restricted cryptocurrency worth over $47 million that originated from illegal activity. Authorities also retrieved approximately 27 million compromised login credentials. Additionally, they were able to take down 326 servers and 142 domains that provided malicious services for malware delivery networks.

"This is a great example of what can happen when government agencies collaborate with the private sector to dismantle the infrastructure used by cybercrime gangs operating at scale," said Alex Cosoi, chief security strategist at Bitdefender. "And I think this shows clearly to those operating malware ecosystems that regardless of how complex your tools may be or how decentralized your network may be, coordinated international efforts will eventually track you down."

All three malware families mentioned above operate using a Malware-as-a-Service (MaaS) business model where customers purchase licenses to deliver additional payloads or steal sensitive information from compromised machines.

Both SocGholish and Amadey act as loaders to introduce second-stage malware onto compromised hosts. SocGholish distributes malware through compromised WordPress websites while Amadey uses phishing campaigns as well as compromised WordPress sites and other loaders, such as Emmenhtal and SmokeLoader.

Active since October 2018, Amadey is written in C++. It advertises itself as a C++-based modular backdoor. Amadey costs its customers $600 for a single license. Customers are charged an additional $50 for each rebuild. The most recent version of Amadey is 5.87. Some examples of commands it supports include:

  • Take a screenshot of the target machine.
  • Download files (DLLs, MSIs, etc.), run them locally on the target machine or store them in a temporary location accessible by the malware.
  • Run local commands using cmd.exe.
  • Create a SOCKS proxy on the target machine.
  • Start a reverse proxy session on the target machine.
  • Establish a remote desktop connection (RDP) on the target machine.
  • Copy the target machine's clipboard content to a remote location.
  • Copy credentials stored in Windows Credential Manager.
  • Enable Remote Desktop (RDP).

According to data published by Mitsui Bussan Secure Directions, the average daily number of active Amadey Command & Control (C2 or C&C) servers ranged between about 2 and 18 until around late August/early September 2022.

However, according to Mitsui Bussan Secure Directions, during the period spanning from January 2023 to early December 2023 the average daily number of active Amadey C2/C&C servers climbed between 5 and 30. Therefore, Mitsui Bussan Secure Directions stated that "it appears that Amadey has become increasingly popular" among cyber-criminal organizations.

Also according to Mitsui Bussan Secure Directions, Amadey experienced a short-lived dormancy beginning in December 2023, after peaking at 17 active C2/C&C servers. However, the average daily number of active Amadey C2/C&C servers has steadily decreased since the end of March 2024.

Additionally, Mitsui Bussan Secure Directions indicated that during the years 2019 through 2024 there was a significant increase in the number of malware samples delivered via Amadey. Specifically, Mitsui Bussan Secure Directions reported that Amadey delivered a record-high number of 11,635 malware samples in 2025, up significantly from previous years' totals of: 66 in 2019; 260 in 2020; 1,231 in 2021; 3,500 in 2022; 8,360 in 2023; and 7,619 in 2024. Furthermore, Mitsui Bussan Secure Directions reported that during 2025 so far (as of mid-year), Amadey has distributed approximately 1,837 payloads.

StealC is another type of malware that has utilized an assortment of entry points to gain unauthorized access to targeted computing resources. These entry points have included malware loaders (such as Amadey) and ClickFix lures. StealC is designed to extract sensitive information such as screenshots, usernames, passwords, session cookies, autofill entries, credit card numbers, browsing history, and extension data from compromised hosts.

StealC first appeared in the wild in January 2023. StealC was marketed for $300/month ($1,000 for six months) by a threat actor utilizing the alias "plymouth". Similar to Amadey, StealC has been continuously updated and maintained by its operators. According to research performed by ESET, as of June 2026, the current version of StealC is version 2.2.1. According to ESET researchers Jakub Tomanek and Tomas Prochazka, StealC's highest concentrations of infections occurred within the U.S., Poland, and Italy.

StealC operates as a secondary loader and can download and execute EXE, MSI, or PowerShell payloads from an outside server upon receiving commands from an attacker's command center. Another feature of StealC includes harvesting information related to desktop applications such as Discord, FileZilla, Foxmail, Microsoft Outlook, Steam, and Telegram. Additionally, StealC can collect information regarding files that match specific names, and can also be configured as a secondary loader to download and execute EXE, MSI, or PowerShell payloads received from an attacker's command center.

One characteristic feature of StealC that differentiates it from other infostealers is that it contains code allowing it to determine whether it is running on a computer whose default language is set to English, Russian, Ukrainian, Belarusian, Kazakh, or Uzbek. If so, StealC will stop execution, as it is programmed to avoid collecting sensitive information (such as usernames, passwords, and clipboard contents) on these types of hosts.

A representative infostealer-to-ransomware attack chain

Earlier this month, CyberArk released details about a Cross-Site Scripting (XSS) vulnerability found in the web-based control panel managed by the StealC operators that allowed researchers to gather insight into MaaS operations. One of the organizations highlighted as a customer of MaaS is YouTubeTA, which has relied on Google's video-sharing platform to advertise cracked copies of Adobe Photoshop and Adobe After Effects. IBM X-Force also identified multiple vulnerabilities found within the C2 panel operated by StealC operators, one of which was a directory-traversal vulnerability allowing researchers to upload a web shell directly to the StealC C2 server. The problem was resolved by StealC operators in February 2026 before being exploited by an affiliate to steal data from other affiliates.

Researchers from Proofpoint stated that "the vulnerability we reported is different from those reported by CyberArk" but further added that "we don't engage in active exploitation or hacking-back-type activities." Researchers did indicate that if "our researchers identify areas of malicious infrastructure/tooling that could be used for investigation purposes," they will report them to relevant authorities.

More in Cybercrime & Law Enforcement

US Officials Crack Down on Malware and Spyware Sellers
Cybercrime

US Officials Crack Down on Malware and Spyware Sellers

Apr 3, 2026 2 min read
Teen Computer Whiz's Journey to Becoming a Crypto Godfather
Cybercrime

Teen Computer Whiz's Journey to Becoming a Crypto Godfather

Mar 29, 2026 1 min read
Mastercard's Deputy Chief Security Officer Alissa Abdullah, PhD Discusses AI and Cybersecurity
Cybercrime

Mastercard's Deputy Chief Security Officer Alissa Abdullah, PhD Discusses AI and Cybersecurity

Mar 29, 2026 1 min read
Australia's SMEs: Key Cyber Threats to Monitor in 2026
Cybercrime

Australia's SMEs: Key Cyber Threats to Monitor in 2026

Mar 24, 2026 2 min read