StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)

StealC Infostealer and Amadey Loader Malware-as-a-Service (TL-2026-0941), also tracked as Operation Endgame (StealC/Amadey phase), is a high-severity malware campaign, first published 2026-06-25. It is attributed to StealC with medium confidence, affects Microsoft Windows, maps to 41 MITRE ATT&CK techniques (T1005, T1008, T1016), and is covered by 9 detection rules and 42 indicators of compromise.

Key facts for TL-2026-0941

Threat ID
TL-2026-0941
Also known as
Operation Endgame (StealC/Amadey phase)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-06-25
Last reviewed
2026-06-25
Attribution
StealC
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial, government, technology, healthcare, retail, cryptocurrency, gaming
Target regions
North America, Europe, South America, Asia, Global
Detection rules
9
Indicators of compromise
42

Malware and tooling in StealC Infostealer and Amadey Loader Malware-as-a-Service

Malware and tooling: Amadey - S1025, Stealc, rundll32.exe

StealC is a malware-as-a-service (MaaS) infostealer that harvests browser credentials, cookies, cryptocurrency wallets, email/FTP clients and gaming data, while Amadey is a modular MaaS loader that fingerprints victims and deploys StealC and other payloads. On June 24, 2026, Microsoft's Digital Crimes Unit, Europol and industry partners executed Operation Endgame, taking down 326 servers, 142 domains and 200+ C2 endpoints tied to roughly 140,000 infections and ~27 million stolen credentials.

How StealC Infostealer and Amadey Loader Malware-as-a-Service works

StealC and Amadey form a tightly coupled commodity-malware ecosystem that powers the modern infostealer-to-ransomware supply chain. Amadey (active since at least 2018, a modular C++ HTTP backdoor sold as a service) acts as the initial loader: it copies itself to a randomly named directory (e.g. nudwee.exe under a numeric folder such as C:\Users\<user>\e079729711), establishes scheduled-task persistence, fingerprints the host (bot ID, version, OS, bitness, admin rights, antivirus, domain) over an RC4-encrypted HTTP POST, and then services a numeric backdoor command set (0x0A-0x1D) to drop EXE/DLL/MSI/PowerShell payloads, run cmd, inject code, start/stop a SOCKS proxy, load credential (cred.dll) and clipboard (clip.dll) plugins, capture screenshots, enable RDP (fDenyTSConnections=0), and create hidden local admin accounts.

StealC is the data-theft endpoint of the chain. After fingerprinting, it registers with its C2 via an RC4-encrypted, Base64-encoded 'create' POST containing the hardware ID and build ID, then receives a JSON configuration (access token, browser-stealing targets, file-grab rules, feature flags). It steals Chromium-family browser data (Chrome, Edge, Brave, Opera, Vivaldi) by injecting a ~165KB payload into a sacrificial CREATE_SUSPENDED process via VirtualAllocEx/WriteProcessMemory/QueueUserAPC to defeat App-Bound Encryption, decrypting output to C:\ProgramData\<HWID>.txt; it also parses Firefox/Gecko profiles, Outlook and Foxmail mail credentials, WinSCP saved sessions, Steam session files, and grabs files per C2 rules. It captures a 90%-quality JPEG desktop screenshot, fetches and runs follow-on payloads (EXE / 'iwr <URL>|iex' PowerShell cradle / msiexec MSI), then self-deletes.

Both families implement CIS-locale guardrails, terminating on Russian, Ukrainian, Belarusian, Kazakh or Uzbek systems, and check Russian/Ukrainian/Belarusian keyboard layouts. Distribution is via SEO poisoning and malvertising pushing trojanized popular software, the ClickFix social-engineering technique (tricking users into pasting a PowerShell cradle into the Run dialog), and targeted phishing. Stolen logs reach dark-web markets within hours ($2-$50 per log, $100+ for bank/corporate logs), feeding initial access brokers and ransomware operators, with enterprise breaches following in 48-72 hours to months. The June 24, 2026 Operation Endgame action (Microsoft DCU, Europol EC3/J-CAT, Eurojust, Germany's BKA, and partners BitSight, ESET, IBM X-Force, Lumen, Mitsui Bussan Secure Directions and Proofpoint) seized 326 servers and 142 domains, disrupted 200+ C2 endpoints, tracked ~27 million stolen credentials, and froze over €41 million (~$47M) in crypto assets.

MITRE ATT&CK techniques used in TL-2026-0941

Collection

T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573.001 Symmetric Cryptography

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery; T1614.001 System Language Discovery

Lateral Movement

T1021.001 Remote Desktop Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task; T1136.001 Local Account; T1547.001 Registry Run Keys / Startup Folder

Privilege Escalation

T1055.004 Asynchronous Procedure Call

Credential Access

T1056.004 Credential API Hooking; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1106 Native API; T1204.002 Malicious File; T1569.002 Service Execution

Initial Access

T1189 Drive-by Compromise; T1195.002 Compromise Software Supply Chain; T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1588.001 Malware

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in StealC Infostealer and Amadey Loader Malware-as-a-Service

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server
  • Google — Chrome / Chromium browsers (Edge, Brave, Opera, Vivaldi)
    Vulnerable versions: App-Bound Encryption builds
  • Mozilla — Firefox / Gecko-based browsers
    Vulnerable versions: all profile-based versions

Remediation for StealC Infostealer and Amadey Loader Malware-as-a-Service

Immediate actions

  • Block all disrupted StealC and Amadey C2 domains and IPs at the perimeter and DNS resolver
  • Force-reset credentials and invalidate browser session cookies for any host showing C2 callbacks or Defender Amadey/StealC alerts
  • Hunt for nudwee.exe and numeric staging folders (e.g. C:\Users\<user>\e079729711) and C:\ProgramData\<HWID>.txt
  • Disable any unexpected fDenyTSConnections=0 RDP enablement and remove unauthorized local admin accounts

Workarounds

  • Disable the Windows Run dialog and clipboard auto-paste for high-risk users to blunt ClickFix
  • Block downloads of trojanized installers via SmartScreen/reputation and allowlisted software sources

Longer-term hardening

  • Deploy EDR with behavioral detection for APC process injection and CREATE_SUSPENDED sacrificial-process patterns
  • Enforce phishing-resistant MFA and hardware-bound session tokens to devalue stolen cookies
  • Restrict execution of PowerShell download cradles (iwr|iex) and msiexec silent installs via WDAC/AppLocker
  • User awareness training on ClickFix Run-dialog paste attacks and SEO-poisoned software downloads

Timeline of StealC Infostealer and Amadey Loader Malware-as-a-Service

  • Amadey modular loader/botnet first emerged and began operating as a malware-as-a-service offering.
  • Trellix researchers reported Amadey and StealC being distributed via self-hosted GitLab instances.
  • In the first two weeks of May 2026, Amadey and StealC were linked to over 140,000 infected computers worldwide.
  • Start of the May 15-June 15, 2026 observed distribution window used to map global infections.
  • End of the observed distribution window; infection telemetry compiled ahead of the disruption action.
  • Microsoft Security Blog published the StealC/Amadey technical breakdown with IOCs and MITRE mappings.
  • Over EUR 41 million (~USD 47 million) in related crypto assets identified and frozen during the operation.
  • Authorities tracked nearly 27 million stolen login credentials tied to the StealC/Amadey ecosystem.
  • Operation Endgame: Microsoft DCU, Europol (EC3/J-CAT), Eurojust, Germany's BKA and industry partners disrupted StealC and Amadey, actioning 326 servers and 142 domains and 200+ C2 endpoints.

Sources cited for StealC Infostealer and Amadey Loader Malware-as-a-Service

Threats related to StealC Infostealer and Amadey Loader Malware-as-a-Service

Detection coverage for TL-2026-0941

As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0941 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats