Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame) — Threadlinqs Intelligence
As of 2026-07-01, Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame) is a high-severity malware threat attributed to Amadey, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1028 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Amadey · FINANCIAL
Microsoft's Digital Crimes Unit used Copilot and other AI tools to accelerate malware code and infrastructure analysis, linking the StealC infostealer and Amadey MaaS loader as a single criminal
On June 24, 2026, Microsoft's Digital Crimes Unit (DCU), together with Europol's European Cybercrime Centre (EC3), Eurojust, Germany's Federal Criminal Police Office (BKA), and law enforcement in Canada, Denmark, the Netherlands, the United Kingdom, and the United States, announced a coordinated disruption of infrastructure supporting the StealC infostealer and the Amadey malware-as-a-service (MaaS) loader as part of the ongoing Operation Endgame initiative. The action followed a related June 18, 2026 disruption of SocGholish (FakeUpdates) infrastructure affecting nearly 15,000 compromised websites.
Microsoft's legal filing, lodged in the U.S. District Court for the Southern District of Florida (Case No. 26-cv-24064-JB), treats Amadey and StealC as components of a single conspiracy under the civil Racketeer Influenced and Corrupt Organizations (RICO) Act, naming five defendants. Steven Masada, assistant general counsel for Microsoft's DCU, said the two malware families were previously tracked as unrelated but AI-assisted analysis using Copilot and related tooling let investigators 'ask questions in plain English instead of manually combing through complex code,' compressing analysis that would normally take 'hours or days into minutes' and surfacing shared C2 infrastructure, encryption keys, campaign/affiliate identifiers, and operational overlap between the two toolsets.
Amadey has operated as a modular Windows malware loader and botnet client since 2018, sold by an actor using the handle '_InCrease_' for roughly $600 in Bitcoin per license plus a $50 rebuild fee. It is typically distributed via SmokeLoader campaigns bundled with cracked/pirated software, and offers plugins for clipboard monitoring/clipping, credential theft, hVNC-based remote access, and generic payload delivery (stealers, cryptominers, RATs, ransomware) to affiliate operators of varying skill levels.
StealC, active since January 2023 and sold by an actor using the handle 'plymouth,' is a C++ information stealer offered as a subscription (roughly $280-$1,000 for one to six months). StealC v2 (current build tracked at v2.22.0/v2.2.4) introduced a streamlined JSON-based C2 protocol, a redesigned web panel with an integrated builder, multi-monitor screenshot capture, a unified file grabber, and an optional loader function allowing operators to specify secondary payload URLs from the C2 panel. It targets credentials and session data from 23+ browsers, 100+ browser extensions, 15+ desktop cryptocurrency wallets, email and FTP clients, gaming platforms, and messaging applications. Victims beacon to StealC C2 servers with 'create' requests to obtain access tokens, then exfiltrate stolen data via 'upload_file' requests carrying RC4-encrypted, Base64-encoded JSON payloads. StealC has been used as a first-stage dropper delivering secondary payloads including Amadey, AsyncRAT, HijackLoader, LockBit Black ransomware, MaskGramStealer, RedLine Stealer, SDBbot, SectopRAT, SmokeLoader, SVCStealer, TinyNuke, Vidar, XMRig, XTinyLoader, and zgRAT/Python-based stealers and crypto clippers -- in one documented chain, StealC delivered XTinyLoader, which in turn deployed LockBit Black ransomware.
Both MaaS platforms use a self-hosted administration-panel model requiring affiliates to run their own backend infrastructure, giving affiliates direct control of victim data and payload distribution while complicating centralized takedown. Investigators (including ESET, which supplied three years of tracking data spanning Q4 2025-H1 2026) identified a directory-traversal vulnerability in the PHP backend of the shared C2 panel software that allowed web-shell upload onto C2 servers, patched by the malware developers in February 2026 -- a bug that assisted defenders' infrastructure mapping.
Disruption metrics reported across partners (figures vary slightly by source and reporting window): 326 servers and 142 domains taken down/seized per Europol; roughly 200 active C2 servers and ~50 d
Target sectors: all sectors opportunistic commodity malware, consumer individual users, government administration, finance, health, critical infrastructure via ransomware handoff
Target regions: Global, india, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1587, T1583, T1588, T1566, T1189, T1204, T1059, T1547, T1053, T1112