Threat reportMalwareTL-2026-1020
Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials
Operation Endgame Disrupts Amadey Loader and StealC (TL-2026-1020), also tracked as Operation Endgame Phase (Amadey/StealC), is a high-severity malware campaign, first published 2026-06-30. It is attributed to InCrease with medium confidence, affects InCrease (criminal developer) Amadey Loader, maps to 28 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 28MITRE ATT&CK
- Actors
- 1InCrease
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-1020
- Threat ID
- TL-2026-1020
- Also known as
- Operation Endgame Phase (Amadey/StealC), StealC you later
- Severity
- HIGH
- Status
- MITIGATED
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- InCrease
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- all sectors opportunistic financially-motivated distribution, finance, critical-infrastructure-adjacent via ransomware access sale
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Operation Endgame Disrupts Amadey Loader and StealC
Malware and tooling: Agent Tesla, Amadey - S1025, AsyncRAT, Lumma Stealer - S1213, PureCrypter, RedLine Stealer - S1240, Rhadmanthys Stealer, Rugmi, Smoke Loader - S0226, SocGholish - S1124, Stealc, Vidar Stealer
How Operation Endgame Disrupts Amadey Loader and StealC works
A multinational law-enforcement action (Europol/Eurojust, Belgium, Canada, Denmark, France, Germany, Netherlands, UK, US) with Bitdefender, Bitsight, ESET, Microsoft, Proofpoint, IBM X-Force, Infoblox, Orange Cyberdefense, Shadowserver and Have I Been Pwned dismantled the infrastructure behind the Amadey loader (v5.87) and StealC infostealer (v2.2.1) between June 15-19, 2026, as the latest phase of Operation Endgame. The action followed a separate takedown of the SocGholish loader days earlier.
Amadey is a C++ modular loader/backdoor active since October 2018, sold as malware-as-a-service (MaaS) by the actor 'InCrease' under a pay-per-rebuild model ($600 single license, $50 per rebuild). It performs machine fingerprinting, downloads secondary payloads (DLL/MSI/PowerShell), executes commands via cmd.exe, captures screenshots, spawns SOCKS proxies and VNC/reverse-proxy sessions, harvests clipboard data and credentials, and can enable RDP. It self-terminates on systems geolocated to Russia, Ukraine, Belarus, Kazakhstan and Uzbekistan, indicating a CIS-based operator base. Amadey has distributed at least 53 unique affiliate clusters of secondary payloads including Lumma Stealer, Vidar Stealer, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer, SmokeLoader, XWorm and AsyncRAT; the largest identified botnet cluster distributed 11 distinct secondary payloads. Sample volume grew from 66 in 2019 to a peak of 11,635 in 2025.
StealC is a C++ infostealer that emerged in January 2023, operated by the actor 'plymouth' and sold via subscription ($300/month or $1,000/six months) with unlimited build generation. It exfiltrates credentials, cookies, autofill data, credit-card data, browsing history and extension data from Chromium-based browsers, and targets Discord, FileZilla, Foxmail, Microsoft Outlook, Steam and Telegram. It supports file-grabbing by naming pattern, functions as a secondary loader (EXE/MSI/PowerShell), and shares Amadey's CIS geofencing logic. StealC is frequently delivered by Amadey and other loaders, and via ClickFix/FileFix social-engineering lures including fake CAPTCHA and fake-video pages; one affiliate cluster ('YouTubeTA') distributed StealC via YouTube ads for cracked Adobe Photoshop/After Effects software.
In January 2026, CyberArk researcher Ari Novick disclosed a stored cross-site scripting (XSS) vulnerability in the StealC web-based C2 admin panel: the panel failed to sanitize user-supplied input, allowing researchers to inject JavaScript that executed in authenticated operator sessions, enabling collection of operator system fingerprints, live session monitoring, and session-cookie exfiltration directly from the criminal C2. A second flaw — a directory-traversal bug in the panel's MetaMask seed-phrase decryption plugin — allowed upload of a PHP web shell: the plugin extracted files from uploaded ZIP archives into a temporary directory without sanitizing path-traversal sequences in filenames, letting a crafted filename escape the temp directory and write an executable web shell to the C2 server. Both flaws were patched by the StealC developers in February 2026, but the directory-traversal bug was reportedly exploited pre-patch by at least one affiliate to steal data from other affiliates, and researcher exploitation of the XSS flaw materially supported the eventual law-enforcement infiltration and disruption of the panel.
Operation Endgame's June 2026 action (June 15-19) dismantled 326 servers and seized 142 domains supporting Amadey and StealC; Microsoft separately identified and sinkholed/blocked over 200 malicious C2 domains and IPs tied to roughly 140,000 infected computers observed in the first two weeks of May 2026 alone, and remediated 18,000 victim computers directly. Investigators recovered 27 million stolen credentials from more than 385,000 compromised systems and froze approximately EUR 41 million ($47 million) in cryptocurrency assets of criminal origin. The action was coordinated by Europol with legal support from Eurojust and led operationally by Germany's Federal Criminal Police Office (BKA), alongside authorities in Belgium, Canada, Denmark, France, the Netherlands, the UK and the US. It followed, by days, a related Operation Endgame action against the SocGholish drive-by-download loader that cleaned roughly 15,000 compromised WordPress sites feeding SocGholish's infection chain.
MITRE ATT&CK techniques used in TL-2026-1020
Collection
T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data; T1560 Archive Collected Data
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Discovery
T1082 System Information Discovery; T1217 Browser Information Discovery; T1614 System Location Discovery
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Persistence
T1505 Server Software Component
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
Impact
Affected products and versions in Operation Endgame Disrupts Amadey Loader and StealC
- InCrease (criminal developer) — Amadey Loader
Vulnerable versions: all versions through 5.87
Fixed in: N/A - infrastructure dismantled by law enforcement - plymouth (criminal developer) — StealC Infostealer
Vulnerable versions: all versions through 2.2.1, C2 panel pre-February 2026 patch
Fixed in: C2 panel XSS/directory-traversal patched February 2026 by criminal developers; infrastructure subsequently dismantled by law enforcement June 2026
Remediation for Operation Endgame Disrupts Amadey Loader and StealC
Patches
- N/A — this is criminal C2 infrastructure, not defender-side software; the StealC developers patched their own panel's XSS and directory-traversal bugs in February 2026
Immediate actions
- Block or sinkhole all previously identified Amadey/StealC C2 domains and IPs at perimeter firewalls and DNS resolvers
- Force credential resets and revoke active sessions for any accounts appearing in the 27M-credential recovery set (via Have I Been Pwned or equivalent breach-check services)
- Hunt for Amadey/StealC-pattern process behavior: unsigned cmd.exe children spawning PowerShell/MSI downloads, unexpected SOCKS proxy or VNC listener creation
- Audit browser credential stores, autofill data, and saved payment cards on any host suspected of infection and rotate associated credentials
- Revoke and rotate crypto wallet seed phrases / private keys on any host that may have run MetaMask alongside a compromised browser
Workarounds
- Disable macro/script execution and restrict PowerShell execution policy on endpoints to reduce Amadey/StealC secondary-payload execution surface
- Restrict outbound access from endpoints to only approved destinations to blunt C2 callback and SOCKS-proxy establishment
Longer-term hardening
- Deploy EDR with behavioral detection tuned to loader/infostealer TTPs (clipboard access, credential-store file reads, screenshot APIs, SOCKS proxy creation)
- Implement application allowlisting to block unauthorized DLL/MSI/PowerShell payload execution from user-writable directories
- User awareness training on ClickFix / FileFix and fake-CAPTCHA social-engineering lures used to deliver StealC and Amadey
- Monitor underground marketplaces and initial-access-broker channels for reappearance of MaaS offerings tied to InCrease/plymouth infrastructure
- Establish continuous IOC feed ingestion from Shadowserver, Spamhaus, and vendor takedown reporting to catch re-infrastructure after law-enforcement disruption
Weaknesses (CWE) in Operation Endgame Disrupts Amadey Loader and StealC
Timeline of Operation Endgame Disrupts Amadey Loader and StealC
- Amadey loader first observed active in the wild, advertised on underground forums by developer 'InCrease' under a pay-per-rebuild MaaS model.
- StealC infostealer emerges, developed and sold via subscription by the actor 'plymouth'; quickly adopted as a common secondary payload delivered by Amadey and other loaders.
- Amadey sample distribution peaks at 11,635 unique samples observed for the year, the highest annual volume recorded.
- CyberArk researcher Ari Novick discloses a stored XSS vulnerability in the StealC web C2 panel, enabling researchers to hijack operator sessions and monitor threat-actor activity from within the criminal infrastructure.
- StealC developers patch the XSS and a separately identified directory-traversal vulnerability in the C2 panel's MetaMask seed-phrase decryption plugin; the traversal bug had reportedly already been exploited by at least one affiliate to steal data from rival affiliates.
- Microsoft observes Amadey and StealC linked to over 140,000 infected computers worldwide during the first two weeks of May 2026.
- A related Operation Endgame action disrupts the SocGholish drive-by-download loader days ahead of the Amadey/StealC phase, cleaning approximately 15,000 compromised WordPress sites used in its infection chain.
- Multinational law-enforcement action against Amadey and StealC infrastructure begins, coordinated by Europol with legal support from Eurojust and operational leadership from Germany's Federal Criminal Police Office (BKA), with authorities from Belgium, Canada, Denmark, France, the Netherlands, the UK and the US.
- Microsoft separately identifies and blocks over 200 malicious C2 domains and IP addresses tied to the campaigns, and directly remediates 18,000 victim computers.
- The two-week Operation Endgame action against Amadey and StealC concludes, resulting in the dismantling of 326 servers, seizure of 142 domains, recovery of 27 million stolen credentials from over 385,000 compromised systems, and the freezing of approximately EUR 41 million ($47 million) in cryptocurrency.
- Europol, Microsoft, Bitdefender, ESET, Proofpoint, IBM X-Force and other private-sector partners publicly announce the Operation Endgame Amadey/StealC disruption results.
Sources cited for Operation Endgame Disrupts Amadey Loader and StealC
- Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
- Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks
- Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers
- Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
- Law enforcement hits StealC and Amadey malware networks
- Operation Endgame Hits StealC and Amadey: 326 Servers Seized, 27 Million Stolen Credentials Recovered
- Europol Disrupts SocGholish, Amadey, and StealC Malware Networks in Global Cyber Strike
- Amadey, StealC malware operations disrupted in Operation Endgame action
- Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks
- StealC you later: Proofpoint and IBM X-Force support Operation Endgame disruptions
- Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations
- Critical XSS Vulnerability in StealC Malware Admin Panel Allows Researchers to Infiltrate and Monitor Threat Actor Operations
- StealC malware control panel flaw leaks details on active attacker
- StealC infrastructure takedown assisted by AI analysis, C2 infiltration
Detection coverage for TL-2026-1020
As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1020 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.