Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized) — Threadlinqs Intelligence
As of 2026-06-30, Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized) is a high-severity malware threat attributed to Amadey (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1022 · Severity: HIGH · Status: MITIGATED · Category: MALWARE
Attribution: Amadey · Russia · FINANCIAL
Europol/Eurojust, Microsoft DCU, Proofpoint, IBM X-Force, ESET, Bitdefender, Bitsight, Infoblox, Orange Cyberdefense, Shadowserver and law enforcement from Belgium, Canada, Denmark, France, Germany,
On June 24, 2026, Europol and Eurojust announced the latest phase of Operation Endgame, a multi-year, multi-agency campaign against malware droppers and infostealers that function as the initial-access 'assembly line' for ransomware and extortion operations. This action, carried out June 15-19, 2026, targeted the Amadey loader/botnet and the StealC information stealer, and followed a related June 18, 2026 disruption of the SocGholish (FakeUpdates) malware framework -- attributed to the Evil Corp criminal group -- which remediated roughly 14,971-15,000 compromised WordPress websites under the same operational umbrella.
Amadey has operated as a paid dropper/loader-as-a-service since October 2018, sold on Russian-language cybercrime forums. It functions as an initial-access broker: distributed via phishing, malvertising, cracked-software downloads, and historically bundled with SmokeLoader (which injects Amadey into Windows Explorer processes), Amadey performs credential harvesting, clipboard hijacking, reconnaissance, and modular follow-on payload delivery, including ransomware and remote access tools. It is used by both financially motivated ransomware affiliates and, per reporting, state-sponsored actors leveraging it for initial access. Researchers identified 53 unique clusters within the Amadey ecosystem, indicating multiple affiliate operators sharing the same core loader.
StealC, first observed in the wild in late 2022/January 2023 and offered as Malware-as-a-Service (MaaS) in C++, is a copycat/evolution of the Vidar and Raccoon infostealer families. StealC harvests browser-stored credentials and cookies, cryptocurrency wallet data (browser extension and desktop wallets), instant-messenger (Telegram) and email client (Outlook) data, gaming platform credentials (Steam), VPN configurations, and performs file-grabbing and multi-monitor screenshot capture. StealC V2 (current as of v2.2.4, released March 2025) introduced a streamlined JSON-based C2 protocol with four operation types (create, upload_file, done, loader), RC4-encrypted traffic (from v2.1.1+), Themida packing, two-stage Base64+RC4 string deobfuscation, CIS-region self-termination checks, duplicate-instance prevention, and (in v1) VM/sandbox detection later removed in v2. The malware is distributed via ClickFix-style social engineering (fake TikTok tutorial videos, FileFix variants prompting victims to paste and execute PowerShell) and via fake Adobe software promoted by a YouTube-based traffic-acquisition affiliate. StealC and Amadey have a bidirectional distribution relationship: Amadey drops StealC, and StealC's loader operation type can in turn deliver additional payloads including Amadey, evidencing coordinated affiliate infrastructure.
The takedown was substantially enabled by two vulnerabilities researchers found in StealC's own PHP-based web control panel. CyberArk researcher Ari Novick disclosed (January 2026) a cross-site scripting flaw in which the panel failed to sanitize user-supplied input, allowing injected JavaScript to execute in the context of an authenticated operator's browser session -- enabling researchers to harvest session cookies, enumerate the operator's browser/system fingerprint, and unmask their real IP address and hardware profile. Separately, IBM X-Force and Proofpoint identified a directory-traversal bug in the panel's file-upload handling: the backend stored uploaded files under their original filename using a sanitization routine that failed to strip forward slashes, allowing a crafted filename with path-traversal sequences to escape the intended temp directory and write a PHP web shell directly to the C2 server filesystem, granting researchers/law enforcement remote code execution on StealC infrastructure ahead of the disruption. Both flaws were patched by the StealC developer in February 2026, after they had already been leveraged for evidence collection and infiltration.
Operational metrics: 326 servers and 142 domains were s
Weaknesses (CWE)
CWE-79, CWE-22
Target sectors: government administration, finance, technology, retail, health, education, critical infrastructure
Target regions: united states of america, poland, italy, North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1189, T1204, T1059, T1547, T1055, T1027, T1140, T1497, T1027