🤔Europol, Microsoft, and law-enforcement partners announced a major cyber strike on June 24, 2026 against SocGholish, Amadey, and StealC malware networks.
— TheDebriefing17 (@TheDebriefing17) June 25, 2026
The action disrupted 326 servers and 142 domains, recovered about 27 million stolen credentials, and identified/restricted… https://t.co/nAShWiZKqK pic.twitter.com/PttyBMU48L
International law enforcement and private-sector partners have disrupted infrastructure tied to StealC, Amadey and SocGholish—malware families used to enable ransomware attacks.
Key takeaways
Operation Endgame targeted infrastructure behind StealC, Amadey and SocGholish.
Authorities and private partners actioned 326 servers and 142 domains.
Investigators recovered roughly 27 million stolen login credentials.
More than €41 million in criminal crypto assets was identified and restricted.
A coordinated strike against malware supply chains
Europol, Eurojust and law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom and the United States have announced a new phase of Operation Endgame, this time targeting malware services that help cybercriminals scale attacks.The action focused on the infrastructure behind SocGholish, Amadey and StealC—three malware families that often sit early in the attack chain. Rather than targeting only individual operators, the operation sought to disrupt the criminal “assembly lines” that feed credential theft, fraud and ransomware deployment.
Why StealC and Amadey matter
StealC is an infostealer built to harvest passwords, browser data, cryptocurrency wallet information and other sensitive details from infected devices. Stolen credentials can be sold, reused in account takeovers, or passed on to initial access brokers that serve ransomware groups.Amadey plays a complementary role. It’s primarily a malware loader, giving attackers a foothold on compromised systems and allowing them to deploy additional payloads. Security researchers say both malware families have been offered through malware-as-a-service models, making them accessible to affiliates with varying levels of skill.
read more:
Replies