All incidents

Europol-led operation dismantles SocGholish, Amadey, and StealC malware networks

malwareclosedJun 24, 2026 — Jun 28, 2026
Europol and Microsoft dismantle StealC and Amadey malware networks

EUROPOL and Microsoft have disrupted the infrastructure behind the StealC and Amadey malware families in a coordinated operation named Endgame according to Europol. The action took place on 24 June 2026 and targeted command‑and‑control servers used by the two infostealers.

StealC is sold as malware‑as‑a‑service and harvests usernames, passwords and session tokens from browsers and applications as outlined by Microsoft. Amadey functions as a dropper that delivers StealC and other payloads, often arriving via phishing emails or compromised websites according to security coverage.

Law‑enforcement officials seized 326 servers and 142 domains associated with the malware, recovering roughly 27 million stolen credentials and freezing more than €41 million in criminal cryptocurrency as reported by SecurityAffairs. The infrastructure was tied to the SocGholish distribution chain, which has been linked to the Russian hacking group Evil Corp since 2018 per Infosecurity Magazine.

By taking aim at the cybercrime‑as‑a‑service model, the operation reduces the capacity of affiliates to launch ransomware attacks and conduct fraud per securityonline. Researchers noted that over 140 000 computers were infected with StealC or Amadey in May 2026, showing the scale of the threat before the disruption per Infosecurity Magazine.

Defenders should enforce strong, unique passwords, enable multi‑factor authentication and monitor authentication logs for unexpected failures or logins from unfamiliar locations as advised by Microsoft. Organisations running WordPress are advised to update core files, themes and plugins immediately and to reset any passwords that may have been exposed in the breach per securityonline.

Security teams are encouraged to share any indicators of compromise with trusted information‑sharing groups and to update detection rules to catch the known behaviours of Amadey and StealC as suggested by SecurityAffairs. Although the takedown has degraded the current infrastructure, threat actors may rebuild, so continued vigilance and regular red‑team exercises are recommended.

Intelligence briefing updated Jun 25, 2026

Evil Corp
Root sourcewww.europol.europa.eu
Timeline Coverage

Swipe to explore timeline