Operation Endgame: Global Law Enforcement Takedown Disrupts SocGholish, Amadey, and StealC Malware-as-a-Service Networks — Threadlinqs Intelligence
As of 2026-06-24, Operation Endgame: Global Law Enforcement Takedown Disrupts SocGholish, Amadey, and StealC Malware-as-a-Service Networks is a high-severity malware threat attributed to InCrease, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0937 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: InCrease · FINANCIAL
A coordinated international operation under the Operation Endgame banner, announced by Europol and the Microsoft Digital Crimes Unit on 24 June 2026, disrupted the distribution and command-and-control
On 24 June 2026, Europol — working with Eurojust, the Microsoft Digital Crimes Unit (DCU), and private-sector partners Bitdefender, Bitsight, and ESET — announced a landmark disruption of the criminal infrastructure behind three of the most widely used Windows commodity malware families as the latest chapter of Operation Endgame. Law-enforcement and judicial authorities from Belgium, Canada, Denmark, France, Germany, the Netherlands, the United Kingdom, and the United States participated. The actions, carried out between 15 and 19 June 2026, targeted the cybercriminal 'assembly lines' — the loaders, stealers, and distribution networks that feed downstream ransomware, financial fraud, and attacks on critical infrastructure — rather than individual infections.
The SocGholish (also tracked as FakeUpdates) network was disrupted first, in actions led by the Netherlands, Canada, the United States, and Germany with Europol and Eurojust support, with public reporting placing the SocGholish action on or around 18 June 2026. SocGholish is a JavaScript-based loader in use since at least 2017, operated by the actor cluster Mustard Tempest (MITRE G1020) and historically used to broker access sold to groups such as Indrik Spider for follow-on RAT and ransomware delivery. It spreads through drive-by 'fake update' lures injected into compromised, legitimate websites — nearly 15,000 compromised WordPress sites were identified and remediated as part of the operation — frequently fronted by traffic-distribution systems such as Parrot TDS and Keitaro TDS and abusing domain shadowing.
The Amadey and StealC disruption was executed jointly with the Microsoft DCU, which severed criminal control of roughly 18,000 victim computers and disabled approximately 200 C2 domains/IPs. Amadey is a modular loader/botnet active since October 2018 (latest tracked version 5.87), sold by a threat actor using the moniker 'InCrease' for roughly USD 600 per license plus USD 50 per rebuild. Amadey performs host fingerprinting, downloads and executes secondary payloads (DLL, MSI, PowerShell), runs commands via cmd.exe, captures screenshots, spawns SOCKS proxies and VNC/reverse-proxy sessions, harvests credentials and clipboard data, and can enable RDP. It is distributed via compromised WordPress sites, phishing, and upstream loaders such as Emmenhtal and SmokeLoader, and across roughly 53 affiliate clusters has delivered Lumma Stealer, Vidar, StealC, RedLine, Rhadamanthys, Agent Tesla, PureCrypter, Rugmi, SmokeLoader, XWorm, and AsyncRAT. Amadey reuses its CreateMutexA mutex name as the RC4 key for encrypting C2 traffic and includes CIS locale checks that disable theft on Russian, Ukrainian, and Belarusian systems.
StealC is a C++ information stealer first observed in January 2023, operated by an actor using the handle 'plymouth'; the StealC v2 line (latest tracked 2.2.1, sold at roughly USD 300/month or USD 1,000 for six months) was rebuilt in early 2025 with server-side decryption, expanded browser/wallet coverage, and PowerShell/MSI loader functionality. It extracts credentials, session cookies, autofill and credit-card data, browsing history, and application data from Chromium browsers and desktop apps (Discord, FileZilla, Foxmail, Outlook, Steam, Telegram), and is delivered via loaders (including Amadey) and ClickFix social-engineering lures. StealC samples are frequently protected with the Themida packer and apply CIS geo-blocking (Russia, Ukraine, Belarus, Kazakhstan, Uzbekistan). In early 2026 the StealC ecosystem itself drew scrutiny: CyberArk disclosed a stored XSS in the StealC web panel (Jan 2026), and a directory-traversal flaw allowing web-shell upload to StealC C2 servers was patched in Feb 2026 after exploitation. Microsoft reported 140,000+ devices infected by the combined operations in the first two weeks of May 2026.
This record documents a defensive intelligence picture of the takedown for SOC hunting and detection validation. Although the crimina
Target sectors: financial, government, healthcare, technology, retail, critical-infrastructure, education
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1189, T1566.002, T1204.001, T1204.002, T1059.007, T1059.001, T1059.003, T1047, T1106, T1547.001