# Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials

> A multinational law-enforcement action (Europol/Eurojust, Belgium, Canada, Denmark, France, Germany, Netherlands, UK, US) with Bitdefender, Bitsight, ESET, Microsoft, Proofpoint, IBM X-Force, Infoblox, Orange Cyberdefense, Shadowserver and Have I Been Pwned dismantled the infrastructure behind the Amadey loader (v5.87) and StealC infostealer (v2.2.1) between June 15-19, 2026, as the latest phase of Operation Endgame. The action followed a separate takedown of the SocGholish loader days earlier.

- **Published:** 2026-06-30T00:00:00Z
- **Last reviewed:** 2026-06-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1020
- **ID:** TL-2026-1020
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** MITIGATED
- **Actor:** InCrease
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Amadey is a C++ modular loader/backdoor active since October 2018, sold as malware-as-a-service (MaaS) by the actor 'InCrease' under a pay-per-rebuild model ($600 single license, $50 per rebuild). It performs machine fingerprinting, downloads secondary payloads (DLL/MSI/PowerShell), executes commands via cmd.exe, captures screenshots, spawns SOCKS proxies and VNC/reverse-proxy sessions, harvests clipboard data and credentials, and can enable RDP. It self-terminates on systems geolocated to Russia, Ukraine, Belarus, Kazakhstan and Uzbekistan, indicating a CIS-based operator base. Amadey has distributed at least 53 unique affiliate clusters of secondary payloads including Lumma Stealer, Vidar Stealer, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer, SmokeLoader, XWorm and AsyncRAT; the largest identified botnet cluster distributed 11 distinct secondary payloads. Sample volume grew from 66 in 2019 to a peak of 11,635 in 2025.

StealC is a C++ infostealer that emerged in January 2023, operated by the actor 'plymouth' and sold via subscription ($300/month or $1,000/six months) with unlimited build generation. It exfiltrates credentials, cookies, autofill data, credit-card data, browsing history and extension data from Chromium-based browsers, and targets Discord, FileZilla, Foxmail, Microsoft Outlook, Steam and Telegram. It supports file-grabbing by naming pattern, functions as a secondary loader (EXE/MSI/PowerShell), and shares Amadey's CIS geofencing logic. StealC is frequently delivered by Amadey and other loaders, and via ClickFix/FileFix social-engineering lures including fake CAPTCHA and fake-video pages; one affiliate cluster ('YouTubeTA') distributed StealC via YouTube ads for cracked Adobe Photoshop/After Effects software.

In January 2026, CyberArk researcher Ari Novick disclosed a stored cross-site scripting (XSS) vulnerability in the StealC web-based C2 admin panel: the panel failed to sanitize user-supplied input, allowing researchers to inject JavaScript that executed in authenticated operator sessions, enabling collection of operator system fingerprints, live session monitoring, and session-cookie exfiltration directly from the criminal C2. A second flaw — a directory-traversal bug in the panel's MetaMask seed-phrase decryption plugin — allowed upload of a PHP web shell: the plugin extracted files from uploaded ZIP archives into a temporary directory without sanitizing path-traversal sequences in filenames, letting a crafted filename escape the temp directory and write an executable web shell to the C2 server. Both flaws were patched by the StealC developers in February 2026, but the directory-traversal bug was reportedly exploited pre-patch by at least one affiliate to steal data from other affiliates, and researcher exploitation of the XSS flaw materially supported the eventual law-enforcement infiltration and disruption of the panel.

Operation Endgame's June 2026 action (June 15-19) dismantled 326 servers and seized 142 domains supporting Amadey and StealC; Microsoft separately identified and sinkholed/blocked over 200 malicious C2 domains and IPs tied to roughly 140,000 infected computers observed in the first two weeks of May 2026 alone, and remediated 18,000 victim computers directly. Investigators recovered 27 million stolen credentials from more than 385,000 compromised systems and froze approximately EUR 41 million ($47 million) in cryptocurrency assets of criminal origin. The action was coordinated by Europol with legal support from Eurojust and led operationally by Germany's Federal Criminal Police Office (BKA), alongside authorities in Belgium, Canada, Denmark, France, the Netherlands, the UK and the US. It followed, by days, a related Operation Endgame action against the SocGholish drive-by-download loader that cleaned roughly 15,000 compromised WordPress sites feeding SocGholish's infection chain.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1566 Phishing
- T1189 Drive-by Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1505 Server Software Component
- T1497 Virtualization/Sandbox Evasion
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1082 System Information Discovery
- T1614 System Location Discovery
- T1217 Browser Information Discovery
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1056 Input Capture
- T1005 Data from Local System
- T1115 Clipboard Data
- T1113 Screen Capture
- T1560 Archive Collected Data
- T1105 Ingress Tool Transfer
- T1090 Proxy
- T1071 Application Layer Protocol
- T1219 Remote Access Tools
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1021 Remote Services

## Sources

- [Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered](https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html)
- [Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks)
- [Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers](https://www.infosecurity-magazine.com/news/operation-endgame-stealc-amadey/)
- [Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame](https://securityaffairs.com/194173/cyber-crime/europol-disrupts-stealc-and-amadey-malware-infrastructure-in-operation-endgame.html)
- [Law enforcement hits StealC and Amadey malware networks](https://www.helpnetsecurity.com/2026/06/24/operation-endgame-stealc-amadey-malware-disrupted/)
- [Operation Endgame Hits StealC and Amadey: 326 Servers Seized, 27 Million Stolen Credentials Recovered](https://breached.company/operation-endgame-stealc-amadey-takedown-2026/)
- [Europol Disrupts SocGholish, Amadey, and StealC Malware Networks in Global Cyber Strike](https://cyberpress.org/europol-socgholish-amadey-stealc-malware/)
- [Amadey, StealC malware operations disrupted in Operation Endgame action](https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/)
- [Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks](https://hackread.com/operation-endgame-stealc-amadey-socgholish-malware/)
- [StealC you later: Proofpoint and IBM X-Force support Operation Endgame disruptions](https://www.ibm.com/think/x-force/stealc-you-later-proofpoint-x-force-support-operation-endgame-disruptions)
- [Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations](https://thehackernews.com/2026/01/security-bug-in-stealc-malware-panel.html)
- [Critical XSS Vulnerability in StealC Malware Admin Panel Allows Researchers to Infiltrate and Monitor Threat Actor Operations](https://www.rescana.com/post/critical-xss-vulnerability-in-stealc-malware-admin-panel-allows-researchers-to-infiltrate-and-monito)
- [StealC malware control panel flaw leaks details on active attacker](https://securityaffairs.com/187075/malware/stealc-malware-control-panel-flaw-leaks-details-on-active-attacker.html)
- [StealC infrastructure takedown assisted by AI analysis, C2 infiltration](https://www.scworld.com/news/stealc-infrastructure-takedown-assisted-by-ai-analysis-c2-infiltration)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1020
