arstechnica.com 6/24/2026, 9:50:44 PM · external

Microsoft led takedown stops Amadey and StealC malware networks

Microsoft led takedown stops Amadey and StealC malware networks
CyberSIXT Evidence Panel
Primary Source blogs.microsoft.com

INTERNATIONAL authorities and tech firms have disrupted a significant cybercrime operation targeting two connected tools, Amadey and StealC. These platforms facilitated the theft of millions in login credentials and over $47 million in ransom payments. Amadey, a malware distribution service, and StealC, an infostealer service, were both exploited by cybercriminals using shared infrastructure.

Microsoft coordinated legal action that led to the cessation of over 200 command-and-control servers and affected 18,000 infected computers. Additionally, 27 million stolen credentials and $47 million in crypto assets were recovered. The operation, involving multiple nations and organizations, also targeted the SocGholish malware, enhancing defenses against cybercrime.

View Primary Source Via arstechnica.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline