StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption) — Threadlinqs Intelligence
As of 2026-06-25, StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption) is a high-severity malware threat attributed to StealC, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-0941 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: StealC · FINANCIAL
StealC is a malware-as-a-service (MaaS) infostealer that harvests browser credentials, cookies, cryptocurrency wallets, email/FTP clients and gaming data, while Amadey is a modular MaaS loader that
StealC and Amadey form a tightly coupled commodity-malware ecosystem that powers the modern infostealer-to-ransomware supply chain. Amadey (active since at least 2018, a modular C++ HTTP backdoor sold as a service) acts as the initial loader: it copies itself to a randomly named directory (e.g. nudwee.exe under a numeric folder such as C:\Users\<user>\e079729711), establishes scheduled-task persistence, fingerprints the host (bot ID, version, OS, bitness, admin rights, antivirus, domain) over an RC4-encrypted HTTP POST, and then services a numeric backdoor command set (0x0A-0x1D) to drop EXE/DLL/MSI/PowerShell payloads, run cmd, inject code, start/stop a SOCKS proxy, load credential (cred.dll) and clipboard (clip.dll) plugins, capture screenshots, enable RDP (fDenyTSConnections=0), and create hidden local admin accounts.
StealC is the data-theft endpoint of the chain. After fingerprinting, it registers with its C2 via an RC4-encrypted, Base64-encoded 'create' POST containing the hardware ID and build ID, then receives a JSON configuration (access token, browser-stealing targets, file-grab rules, feature flags). It steals Chromium-family browser data (Chrome, Edge, Brave, Opera, Vivaldi) by injecting a ~165KB payload into a sacrificial CREATE_SUSPENDED process via VirtualAllocEx/WriteProcessMemory/QueueUserAPC to defeat App-Bound Encryption, decrypting output to C:\ProgramData\<HWID>.txt; it also parses Firefox/Gecko profiles, Outlook and Foxmail mail credentials, WinSCP saved sessions, Steam session files, and grabs files per C2 rules. It captures a 90%-quality JPEG desktop screenshot, fetches and runs follow-on payloads (EXE / 'iwr <URL>|iex' PowerShell cradle / msiexec MSI), then self-deletes.
Both families implement CIS-locale guardrails, terminating on Russian, Ukrainian, Belarusian, Kazakh or Uzbek systems, and check Russian/Ukrainian/Belarusian keyboard layouts. Distribution is via SEO poisoning and malvertising pushing trojanized popular software, the ClickFix social-engineering technique (tricking users into pasting a PowerShell cradle into the Run dialog), and targeted phishing. Stolen logs reach dark-web markets within hours ($2-$50 per log, $100+ for bank/corporate logs), feeding initial access brokers and ransomware operators, with enterprise breaches following in 48-72 hours to months. The June 24, 2026 Operation Endgame action (Microsoft DCU, Europol EC3/J-CAT, Eurojust, Germany's BKA, and partners BitSight, ESET, IBM X-Force, Lumen, Mitsui Bussan Secure Directions and Proofpoint) seized 326 servers and 142 domains, disrupted 200+ C2 endpoints, tracked ~27 million stolen credentials, and froze over €41 million (~$47M) in crypto assets.
Target sectors: financial, government, technology, healthcare, retail, cryptocurrency, gaming
Target regions: North America, Europe, South America, Asia, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1588.001, T1566, T1189, T1195.002, T1059.001, T1059.003, T1204.002, T1106, T1569.002