Threat reportMalwareTL-2026-1020

Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials

highMITIGATED

Operation Endgame Disrupts Amadey Loader and StealC (TL-2026-1020), also tracked as Operation Endgame Phase (Amadey/StealC), is a high-severity malware campaign, first published 2026-06-30. It is attributed to InCrease with medium confidence, affects InCrease (criminal developer) Amadey Loader, maps to 28 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
28MITRE ATT&CK
Actors
1InCrease
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-1020

Threat ID
TL-2026-1020
Also known as
Operation Endgame Phase (Amadey/StealC), StealC you later
Severity
HIGH
Status
MITIGATED
Category
MALWARE
First published
Last reviewed
Attribution
InCrease
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
all sectors opportunistic financially-motivated distribution, finance, critical-infrastructure-adjacent via ransomware access sale
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
25

Malware and tooling in Operation Endgame Disrupts Amadey Loader and StealC

Malware and tooling: Agent Tesla, Amadey - S1025, AsyncRAT, Lumma Stealer - S1213, PureCrypter, RedLine Stealer - S1240, Rhadmanthys Stealer, Rugmi, Smoke Loader - S0226, SocGholish - S1124, Stealc, Vidar Stealer

How Operation Endgame Disrupts Amadey Loader and StealC works

A multinational law-enforcement action (Europol/Eurojust, Belgium, Canada, Denmark, France, Germany, Netherlands, UK, US) with Bitdefender, Bitsight, ESET, Microsoft, Proofpoint, IBM X-Force, Infoblox, Orange Cyberdefense, Shadowserver and Have I Been Pwned dismantled the infrastructure behind the Amadey loader (v5.87) and StealC infostealer (v2.2.1) between June 15-19, 2026, as the latest phase of Operation Endgame. The action followed a separate takedown of the SocGholish loader days earlier.

Amadey is a C++ modular loader/backdoor active since October 2018, sold as malware-as-a-service (MaaS) by the actor 'InCrease' under a pay-per-rebuild model ($600 single license, $50 per rebuild). It performs machine fingerprinting, downloads secondary payloads (DLL/MSI/PowerShell), executes commands via cmd.exe, captures screenshots, spawns SOCKS proxies and VNC/reverse-proxy sessions, harvests clipboard data and credentials, and can enable RDP. It self-terminates on systems geolocated to Russia, Ukraine, Belarus, Kazakhstan and Uzbekistan, indicating a CIS-based operator base. Amadey has distributed at least 53 unique affiliate clusters of secondary payloads including Lumma Stealer, Vidar Stealer, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer, SmokeLoader, XWorm and AsyncRAT; the largest identified botnet cluster distributed 11 distinct secondary payloads. Sample volume grew from 66 in 2019 to a peak of 11,635 in 2025.

StealC is a C++ infostealer that emerged in January 2023, operated by the actor 'plymouth' and sold via subscription ($300/month or $1,000/six months) with unlimited build generation. It exfiltrates credentials, cookies, autofill data, credit-card data, browsing history and extension data from Chromium-based browsers, and targets Discord, FileZilla, Foxmail, Microsoft Outlook, Steam and Telegram. It supports file-grabbing by naming pattern, functions as a secondary loader (EXE/MSI/PowerShell), and shares Amadey's CIS geofencing logic. StealC is frequently delivered by Amadey and other loaders, and via ClickFix/FileFix social-engineering lures including fake CAPTCHA and fake-video pages; one affiliate cluster ('YouTubeTA') distributed StealC via YouTube ads for cracked Adobe Photoshop/After Effects software.

In January 2026, CyberArk researcher Ari Novick disclosed a stored cross-site scripting (XSS) vulnerability in the StealC web-based C2 admin panel: the panel failed to sanitize user-supplied input, allowing researchers to inject JavaScript that executed in authenticated operator sessions, enabling collection of operator system fingerprints, live session monitoring, and session-cookie exfiltration directly from the criminal C2. A second flaw — a directory-traversal bug in the panel's MetaMask seed-phrase decryption plugin — allowed upload of a PHP web shell: the plugin extracted files from uploaded ZIP archives into a temporary directory without sanitizing path-traversal sequences in filenames, letting a crafted filename escape the temp directory and write an executable web shell to the C2 server. Both flaws were patched by the StealC developers in February 2026, but the directory-traversal bug was reportedly exploited pre-patch by at least one affiliate to steal data from other affiliates, and researcher exploitation of the XSS flaw materially supported the eventual law-enforcement infiltration and disruption of the panel.

Operation Endgame's June 2026 action (June 15-19) dismantled 326 servers and seized 142 domains supporting Amadey and StealC; Microsoft separately identified and sinkholed/blocked over 200 malicious C2 domains and IPs tied to roughly 140,000 infected computers observed in the first two weeks of May 2026 alone, and remediated 18,000 victim computers directly. Investigators recovered 27 million stolen credentials from more than 385,000 compromised systems and froze approximately EUR 41 million ($47 million) in cryptocurrency assets of criminal origin. The action was coordinated by Europol with legal support from Eurojust and led operationally by Germany's Federal Criminal Police Office (BKA), alongside authorities in Belgium, Canada, Denmark, France, the Netherlands, the UK and the US. It followed, by days, a related Operation Endgame action against the SocGholish drive-by-download loader that cleaned roughly 15,000 compromised WordPress sites feeding SocGholish's infection chain.

MITRE ATT&CK techniques used in TL-2026-1020

Collection

T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data; T1560 Archive Collected Data

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery; T1614 System Location Discovery

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Persistence

T1505 Server Software Component

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

Impact

T1657 Financial Theft

Affected products and versions in Operation Endgame Disrupts Amadey Loader and StealC

  • InCrease (criminal developer) — Amadey Loader
    Vulnerable versions: all versions through 5.87
    Fixed in: N/A - infrastructure dismantled by law enforcement
  • plymouth (criminal developer) — StealC Infostealer
    Vulnerable versions: all versions through 2.2.1, C2 panel pre-February 2026 patch
    Fixed in: C2 panel XSS/directory-traversal patched February 2026 by criminal developers; infrastructure subsequently dismantled by law enforcement June 2026

Remediation for Operation Endgame Disrupts Amadey Loader and StealC

Patches

  • N/A — this is criminal C2 infrastructure, not defender-side software; the StealC developers patched their own panel's XSS and directory-traversal bugs in February 2026

Immediate actions

  • Block or sinkhole all previously identified Amadey/StealC C2 domains and IPs at perimeter firewalls and DNS resolvers
  • Force credential resets and revoke active sessions for any accounts appearing in the 27M-credential recovery set (via Have I Been Pwned or equivalent breach-check services)
  • Hunt for Amadey/StealC-pattern process behavior: unsigned cmd.exe children spawning PowerShell/MSI downloads, unexpected SOCKS proxy or VNC listener creation
  • Audit browser credential stores, autofill data, and saved payment cards on any host suspected of infection and rotate associated credentials
  • Revoke and rotate crypto wallet seed phrases / private keys on any host that may have run MetaMask alongside a compromised browser

Workarounds

  • Disable macro/script execution and restrict PowerShell execution policy on endpoints to reduce Amadey/StealC secondary-payload execution surface
  • Restrict outbound access from endpoints to only approved destinations to blunt C2 callback and SOCKS-proxy establishment

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to loader/infostealer TTPs (clipboard access, credential-store file reads, screenshot APIs, SOCKS proxy creation)
  • Implement application allowlisting to block unauthorized DLL/MSI/PowerShell payload execution from user-writable directories
  • User awareness training on ClickFix / FileFix and fake-CAPTCHA social-engineering lures used to deliver StealC and Amadey
  • Monitor underground marketplaces and initial-access-broker channels for reappearance of MaaS offerings tied to InCrease/plymouth infrastructure
  • Establish continuous IOC feed ingestion from Shadowserver, Spamhaus, and vendor takedown reporting to catch re-infrastructure after law-enforcement disruption

Weaknesses (CWE) in Operation Endgame Disrupts Amadey Loader and StealC

CWE-79, CWE-22

Timeline of Operation Endgame Disrupts Amadey Loader and StealC

  • Amadey loader first observed active in the wild, advertised on underground forums by developer 'InCrease' under a pay-per-rebuild MaaS model.
  • StealC infostealer emerges, developed and sold via subscription by the actor 'plymouth'; quickly adopted as a common secondary payload delivered by Amadey and other loaders.
  • Amadey sample distribution peaks at 11,635 unique samples observed for the year, the highest annual volume recorded.
  • CyberArk researcher Ari Novick discloses a stored XSS vulnerability in the StealC web C2 panel, enabling researchers to hijack operator sessions and monitor threat-actor activity from within the criminal infrastructure.
  • StealC developers patch the XSS and a separately identified directory-traversal vulnerability in the C2 panel's MetaMask seed-phrase decryption plugin; the traversal bug had reportedly already been exploited by at least one affiliate to steal data from rival affiliates.
  • Microsoft observes Amadey and StealC linked to over 140,000 infected computers worldwide during the first two weeks of May 2026.
  • A related Operation Endgame action disrupts the SocGholish drive-by-download loader days ahead of the Amadey/StealC phase, cleaning approximately 15,000 compromised WordPress sites used in its infection chain.
  • Multinational law-enforcement action against Amadey and StealC infrastructure begins, coordinated by Europol with legal support from Eurojust and operational leadership from Germany's Federal Criminal Police Office (BKA), with authorities from Belgium, Canada, Denmark, France, the Netherlands, the UK and the US.
  • Microsoft separately identifies and blocks over 200 malicious C2 domains and IP addresses tied to the campaigns, and directly remediates 18,000 victim computers.
  • The two-week Operation Endgame action against Amadey and StealC concludes, resulting in the dismantling of 326 servers, seizure of 142 domains, recovery of 27 million stolen credentials from over 385,000 compromised systems, and the freezing of approximately EUR 41 million ($47 million) in cryptocurrency.
  • Europol, Microsoft, Bitdefender, ESET, Proofpoint, IBM X-Force and other private-sector partners publicly announce the Operation Endgame Amadey/StealC disruption results.

Sources cited for Operation Endgame Disrupts Amadey Loader and StealC

Detection coverage for TL-2026-1020

As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1020 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats