StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)
StealC Infostealer and Amadey Loader Malware-as-a-Service (TL-2026-0941), also tracked as Operation Endgame (StealC/Amadey phase), is a high-severity malware campaign, first published 2026-06-25. It is attributed to StealC with medium confidence, affects Microsoft Windows, maps to 41 MITRE ATT&CK techniques (T1005, T1008, T1016), and is covered by 9 detection rules and 42 indicators of compromise.
Key facts for TL-2026-0941
- Threat ID
- TL-2026-0941
- Also known as
- Operation Endgame (StealC/Amadey phase)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-25
- Last reviewed
- 2026-06-25
- Attribution
- StealC
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial, government, technology, healthcare, retail, cryptocurrency, gaming
- Target regions
- North America, Europe, South America, Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 42
Malware and tooling in StealC Infostealer and Amadey Loader Malware-as-a-Service
Malware and tooling: Amadey - S1025, Stealc, rundll32.exe
StealC is a malware-as-a-service (MaaS) infostealer that harvests browser credentials, cookies, cryptocurrency wallets, email/FTP clients and gaming data, while Amadey is a modular MaaS loader that fingerprints victims and deploys StealC and other payloads. On June 24, 2026, Microsoft's Digital Crimes Unit, Europol and industry partners executed Operation Endgame, taking down 326 servers, 142 domains and 200+ C2 endpoints tied to roughly 140,000 infections and ~27 million stolen credentials.
How StealC Infostealer and Amadey Loader Malware-as-a-Service works
StealC and Amadey form a tightly coupled commodity-malware ecosystem that powers the modern infostealer-to-ransomware supply chain. Amadey (active since at least 2018, a modular C++ HTTP backdoor sold as a service) acts as the initial loader: it copies itself to a randomly named directory (e.g. nudwee.exe under a numeric folder such as C:\Users\<user>\e079729711), establishes scheduled-task persistence, fingerprints the host (bot ID, version, OS, bitness, admin rights, antivirus, domain) over an RC4-encrypted HTTP POST, and then services a numeric backdoor command set (0x0A-0x1D) to drop EXE/DLL/MSI/PowerShell payloads, run cmd, inject code, start/stop a SOCKS proxy, load credential (cred.dll) and clipboard (clip.dll) plugins, capture screenshots, enable RDP (fDenyTSConnections=0), and create hidden local admin accounts.
StealC is the data-theft endpoint of the chain. After fingerprinting, it registers with its C2 via an RC4-encrypted, Base64-encoded 'create' POST containing the hardware ID and build ID, then receives a JSON configuration (access token, browser-stealing targets, file-grab rules, feature flags). It steals Chromium-family browser data (Chrome, Edge, Brave, Opera, Vivaldi) by injecting a ~165KB payload into a sacrificial CREATE_SUSPENDED process via VirtualAllocEx/WriteProcessMemory/QueueUserAPC to defeat App-Bound Encryption, decrypting output to C:\ProgramData\<HWID>.txt; it also parses Firefox/Gecko profiles, Outlook and Foxmail mail credentials, WinSCP saved sessions, Steam session files, and grabs files per C2 rules. It captures a 90%-quality JPEG desktop screenshot, fetches and runs follow-on payloads (EXE / 'iwr <URL>|iex' PowerShell cradle / msiexec MSI), then self-deletes.
Both families implement CIS-locale guardrails, terminating on Russian, Ukrainian, Belarusian, Kazakh or Uzbek systems, and check Russian/Ukrainian/Belarusian keyboard layouts. Distribution is via SEO poisoning and malvertising pushing trojanized popular software, the ClickFix social-engineering technique (tricking users into pasting a PowerShell cradle into the Run dialog), and targeted phishing. Stolen logs reach dark-web markets within hours ($2-$50 per log, $100+ for bank/corporate logs), feeding initial access brokers and ransomware operators, with enterprise breaches following in 48-72 hours to months. The June 24, 2026 Operation Endgame action (Microsoft DCU, Europol EC3/J-CAT, Eurojust, Germany's BKA, and partners BitSight, ESET, IBM X-Force, Lumen, Mitsui Bussan Secure Directions and Proofpoint) seized 326 servers and 142 domains, disrupted 200+ C2 endpoints, tracked ~27 million stolen credentials, and froze over €41 million (~$47M) in crypto assets.
MITRE ATT&CK techniques used in TL-2026-0941
Collection
T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data
Command and Control
T1008 Fallback Channels; T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573.001 Symmetric Cryptography
Discovery
T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery; T1614.001 System Language Discovery
Lateral Movement
T1021.001 Remote Desktop Protocol
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053.005 Scheduled Task; T1136.001 Local Account; T1547.001 Registry Run Keys / Startup Folder
Privilege Escalation
T1055.004 Asynchronous Procedure Call
Credential Access
T1056.004 Credential API Hooking; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1106 Native API; T1204.002 Malicious File; T1569.002 Service Execution
Initial Access
T1189 Drive-by Compromise; T1195.002 Compromise Software Supply Chain; T1566 Phishing
Resource Development
T1583 Acquire Infrastructure; T1588.001 Malware
defense-impairment
Affected products and versions in StealC Infostealer and Amadey Loader Malware-as-a-Service
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server - Google — Chrome / Chromium browsers (Edge, Brave, Opera, Vivaldi)
Vulnerable versions: App-Bound Encryption builds - Mozilla — Firefox / Gecko-based browsers
Vulnerable versions: all profile-based versions
Remediation for StealC Infostealer and Amadey Loader Malware-as-a-Service
Immediate actions
- Block all disrupted StealC and Amadey C2 domains and IPs at the perimeter and DNS resolver
- Force-reset credentials and invalidate browser session cookies for any host showing C2 callbacks or Defender Amadey/StealC alerts
- Hunt for nudwee.exe and numeric staging folders (e.g. C:\Users\<user>\e079729711) and C:\ProgramData\<HWID>.txt
- Disable any unexpected fDenyTSConnections=0 RDP enablement and remove unauthorized local admin accounts
Workarounds
- Disable the Windows Run dialog and clipboard auto-paste for high-risk users to blunt ClickFix
- Block downloads of trojanized installers via SmartScreen/reputation and allowlisted software sources
Longer-term hardening
- Deploy EDR with behavioral detection for APC process injection and CREATE_SUSPENDED sacrificial-process patterns
- Enforce phishing-resistant MFA and hardware-bound session tokens to devalue stolen cookies
- Restrict execution of PowerShell download cradles (iwr|iex) and msiexec silent installs via WDAC/AppLocker
- User awareness training on ClickFix Run-dialog paste attacks and SEO-poisoned software downloads
Timeline of StealC Infostealer and Amadey Loader Malware-as-a-Service
- Amadey modular loader/botnet first emerged and began operating as a malware-as-a-service offering.
- Trellix researchers reported Amadey and StealC being distributed via self-hosted GitLab instances.
- In the first two weeks of May 2026, Amadey and StealC were linked to over 140,000 infected computers worldwide.
- Start of the May 15-June 15, 2026 observed distribution window used to map global infections.
- End of the observed distribution window; infection telemetry compiled ahead of the disruption action.
- Microsoft Security Blog published the StealC/Amadey technical breakdown with IOCs and MITRE mappings.
- Over EUR 41 million (~USD 47 million) in related crypto assets identified and frozen during the operation.
- Authorities tracked nearly 27 million stolen login credentials tied to the StealC/Amadey ecosystem.
- Operation Endgame: Microsoft DCU, Europol (EC3/J-CAT), Eurojust, Germany's BKA and industry partners disrupted StealC and Amadey, actioning 326 servers and 142 domains and 200+ C2 endpoints.
Sources cited for StealC Infostealer and Amadey Loader Malware-as-a-Service
- StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
- Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers
- Law enforcement hits StealC and Amadey malware networks (Operation Endgame)
- ESET takes part in global Operation Endgame to disrupt Amadey botnet and Stealc infostealer
- Bitsight Aids Disruption Efforts on Amadey & StealC Malware
- Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
- Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks
Threats related to StealC Infostealer and Amadey Loader Malware-as-a-Service
- FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai
- Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage
- Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent Malvertising Campaign Deploys SectopRAT via Trojanized Claude Desktop Installer
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 Implant
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor
- Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) Malware
Detection coverage for TL-2026-0941
As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0941 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.