Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials — Threadlinqs Intelligence
As of 2026-06-30, Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials is a high-severity malware threat attributed to InCrease, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1020 · Severity: HIGH · Status: MITIGATED · Category: MALWARE
Attribution: InCrease · FINANCIAL
A multinational law-enforcement action (Europol/Eurojust, Belgium, Canada, Denmark, France, Germany, Netherlands, UK, US) with Bitdefender, Bitsight, ESET, Microsoft, Proofpoint, IBM X-Force,
Amadey is a C++ modular loader/backdoor active since October 2018, sold as malware-as-a-service (MaaS) by the actor 'InCrease' under a pay-per-rebuild model ($600 single license, $50 per rebuild). It performs machine fingerprinting, downloads secondary payloads (DLL/MSI/PowerShell), executes commands via cmd.exe, captures screenshots, spawns SOCKS proxies and VNC/reverse-proxy sessions, harvests clipboard data and credentials, and can enable RDP. It self-terminates on systems geolocated to Russia, Ukraine, Belarus, Kazakhstan and Uzbekistan, indicating a CIS-based operator base. Amadey has distributed at least 53 unique affiliate clusters of secondary payloads including Lumma Stealer, Vidar Stealer, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer, SmokeLoader, XWorm and AsyncRAT; the largest identified botnet cluster distributed 11 distinct secondary payloads. Sample volume grew from 66 in 2019 to a peak of 11,635 in 2025.
StealC is a C++ infostealer that emerged in January 2023, operated by the actor 'plymouth' and sold via subscription ($300/month or $1,000/six months) with unlimited build generation. It exfiltrates credentials, cookies, autofill data, credit-card data, browsing history and extension data from Chromium-based browsers, and targets Discord, FileZilla, Foxmail, Microsoft Outlook, Steam and Telegram. It supports file-grabbing by naming pattern, functions as a secondary loader (EXE/MSI/PowerShell), and shares Amadey's CIS geofencing logic. StealC is frequently delivered by Amadey and other loaders, and via ClickFix/FileFix social-engineering lures including fake CAPTCHA and fake-video pages; one affiliate cluster ('YouTubeTA') distributed StealC via YouTube ads for cracked Adobe Photoshop/After Effects software.
In January 2026, CyberArk researcher Ari Novick disclosed a stored cross-site scripting (XSS) vulnerability in the StealC web-based C2 admin panel: the panel failed to sanitize user-supplied input, allowing researchers to inject JavaScript that executed in authenticated operator sessions, enabling collection of operator system fingerprints, live session monitoring, and session-cookie exfiltration directly from the criminal C2. A second flaw — a directory-traversal bug in the panel's MetaMask seed-phrase decryption plugin — allowed upload of a PHP web shell: the plugin extracted files from uploaded ZIP archives into a temporary directory without sanitizing path-traversal sequences in filenames, letting a crafted filename escape the temp directory and write an executable web shell to the C2 server. Both flaws were patched by the StealC developers in February 2026, but the directory-traversal bug was reportedly exploited pre-patch by at least one affiliate to steal data from other affiliates, and researcher exploitation of the XSS flaw materially supported the eventual law-enforcement infiltration and disruption of the panel.
Operation Endgame's June 2026 action (June 15-19) dismantled 326 servers and seized 142 domains supporting Amadey and StealC; Microsoft separately identified and sinkholed/blocked over 200 malicious C2 domains and IPs tied to roughly 140,000 infected computers observed in the first two weeks of May 2026 alone, and remediated 18,000 victim computers directly. Investigators recovered 27 million stolen credentials from more than 385,000 compromised systems and froze approximately EUR 41 million ($47 million) in cryptocurrency assets of criminal origin. The action was coordinated by Europol with legal support from Eurojust and led operationally by Germany's Federal Criminal Police Office (BKA), alongside authorities in Belgium, Canada, Denmark, France, the Netherlands, the UK and the US. It followed, by days, a related Operation Endgame action against the SocGholish drive-by-download loader that cleaned roughly 15,000 compromised WordPress sites feeding SocGholish's infection chain.
Weaknesses (CWE)
CWE-79, CWE-22
Target sectors: all sectors opportunistic financially-motivated distribution, finance, critical-infrastructure-adjacent via ransomware access sale
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1587, T1588, T1566, T1189, T1059, T1059, T1204, T1505, T1497