securityaffairs.com 6/24/2026, 7:31:05 PM · external

Europol seizes StealC, Amadey, SocGholish in Operation Endgame

Europol seizes StealC, Amadey, SocGholish in Operation Endgame
Developing story malware 3 articles tracked
Europol and Microsoft dismantle StealC and Amadey malware networks
CyberSIXT Evidence Panel
Primary Source europol.europa.eu
Threat Actor

EUROPOL'S Operation Endgame disrupted the infrastructure of malware services StealC, Amadey, and SocGholish from June 15-19, 2026. The operation involved multiple international law enforcement agencies and private firms targeting malware that facilitates ransomware and fraud. Key outcomes included the dismantling of 326 servers and 142 domains, recovering 27 million stolen credentials, and restricting over €41 million in criminal cryptocurrency assets.

SocGholish, linked to Evil Corp, injects malicious prompts into legitimate sites, while Amadey spreads through phishing and acts as a dropper for other malware. The operation aims to undermine the cybercrime supply chain by targeting initial access malware, significantly decreasing the capability of cybercriminals to launch attacks.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline