Threat reportMalwareTL-2026-1028
Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame)
Microsoft AI-Assisted Investigation Links StealC and Amadey (TL-2026-1028), also tracked as Operation Endgame (June 2026 phase), is a high-severity malware campaign, first published 2026-07-01. It is attributed to Amadey with medium confidence, affects N/A (criminal MaaS platform) Amadey botnet/loader, maps to 30 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 30MITRE ATT&CK
- Actors
- 2Amadey
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-1028
- Threat ID
- TL-2026-1028
- Also known as
- Operation Endgame (June 2026 phase), Amadey/StealC Takedown, Microsoft v. Doe (Amadey/StealC RICO action)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Amadey, StealC Malware-as-a-Service Enterprise
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- all sectors opportunistic commodity malware, consumer individual users, government administration, finance, health, critical infrastructure via ransomware handoff
- Target regions
- Global, india, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Microsoft AI-Assisted Investigation Links StealC and Amadey
Malware and tooling: Amadey - S1025, AsyncRAT, HijackLoader, LockBit 3.0 - S1202, MaskGramStealer, RedLine Stealer - S1240, SDBbot, SVCStealer, SectopRAT, Smoke Loader - S0226, SocGholish - S1124, Stealc
How Microsoft AI-Assisted Investigation Links StealC and Amadey works
Microsoft's Digital Crimes Unit used Copilot and other AI tools to accelerate malware code and infrastructure analysis, linking the StealC infostealer and Amadey MaaS loader as a single criminal enterprise and underpinning a civil RICO suit against five defendants. Coordinated with Europol/Eurojust as part of Operation Endgame, the action disrupted 326 servers and 142 domains, recovered ~27 million stolen credentials from 385,000+ compromised systems, and froze roughly $47 million (€41M) in cryptocurrency.
On June 24, 2026, Microsoft's Digital Crimes Unit (DCU), together with Europol's European Cybercrime Centre (EC3), Eurojust, Germany's Federal Criminal Police Office (BKA), and law enforcement in Canada, Denmark, the Netherlands, the United Kingdom, and the United States, announced a coordinated disruption of infrastructure supporting the StealC infostealer and the Amadey malware-as-a-service (MaaS) loader as part of the ongoing Operation Endgame initiative. The action followed a related June 18, 2026 disruption of SocGholish (FakeUpdates) infrastructure affecting nearly 15,000 compromised websites.
Microsoft's legal filing, lodged in the U.S. District Court for the Southern District of Florida (Case No. 26-cv-24064-JB), treats Amadey and StealC as components of a single conspiracy under the civil Racketeer Influenced and Corrupt Organizations (RICO) Act, naming five defendants. Steven Masada, assistant general counsel for Microsoft's DCU, said the two malware families were previously tracked as unrelated but AI-assisted analysis using Copilot and related tooling let investigators 'ask questions in plain English instead of manually combing through complex code,' compressing analysis that would normally take 'hours or days into minutes' and surfacing shared C2 infrastructure, encryption keys, campaign/affiliate identifiers, and operational overlap between the two toolsets.
Amadey has operated as a modular Windows malware loader and botnet client since 2018, sold by an actor using the handle '_InCrease_' for roughly $600 in Bitcoin per license plus a $50 rebuild fee. It is typically distributed via SmokeLoader campaigns bundled with cracked/pirated software, and offers plugins for clipboard monitoring/clipping, credential theft, hVNC-based remote access, and generic payload delivery (stealers, cryptominers, RATs, ransomware) to affiliate operators of varying skill levels.
StealC, active since January 2023 and sold by an actor using the handle 'plymouth,' is a C++ information stealer offered as a subscription (roughly $280-$1,000 for one to six months). StealC v2 (current build tracked at v2.22.0/v2.2.4) introduced a streamlined JSON-based C2 protocol, a redesigned web panel with an integrated builder, multi-monitor screenshot capture, a unified file grabber, and an optional loader function allowing operators to specify secondary payload URLs from the C2 panel. It targets credentials and session data from 23+ browsers, 100+ browser extensions, 15+ desktop cryptocurrency wallets, email and FTP clients, gaming platforms, and messaging applications. Victims beacon to StealC C2 servers with 'create' requests to obtain access tokens, then exfiltrate stolen data via 'upload_file' requests carrying RC4-encrypted, Base64-encoded JSON payloads. StealC has been used as a first-stage dropper delivering secondary payloads including Amadey, AsyncRAT, HijackLoader, LockBit Black ransomware, MaskGramStealer, RedLine Stealer, SDBbot, SectopRAT, SmokeLoader, SVCStealer, TinyNuke, Vidar, XMRig, XTinyLoader, and zgRAT/Python-based stealers and crypto clippers -- in one documented chain, StealC delivered XTinyLoader, which in turn deployed LockBit Black ransomware.
Both MaaS platforms use a self-hosted administration-panel model requiring affiliates to run their own backend infrastructure, giving affiliates direct control of victim data and payload distribution while complicating centralized takedown. Investigators (including ESET, which supplied three years of tracking data spanning Q4 2025-H1 2026) identified a directory-traversal vulnerability in the PHP backend of the shared C2 panel software that allowed web-shell upload onto C2 servers, patched by the malware developers in February 2026 -- a bug that assisted defenders' infrastructure mapping.
Disruption metrics reported across partners (figures vary slightly by source and reporting window): 326 servers and 142 domains taken down/seized per Europol; roughly 200 active C2 servers and ~50 domains reported by ESET; Bitsight independently identified 182 combined C2 infrastructure points (47 domains, 34 Amadey core C2 IPs, 69 Amadey task C2 IPs, 79 StealC IPs); Proofpoint/IBM X-Force cited 66 domains and 296 servers. Amadey sinkhole telemetry over a 90-day window logged roughly 200,000 infected IPs, concentrated in India; StealC log analysis from a January 2025 sample set identified roughly 5,000 victim machines. Microsoft reported 140,000+ infected computers linked to the two malware families in the first two weeks of May 2026 alone, and separately identified and severed criminal control over 18,000+ victim computers. Approximately 27 million stolen credentials were recovered from more than 385,000 compromised systems. Investigators identified and froze roughly €41 million (~$47 million) in cryptocurrency assets linked to the criminal enterprise (a figure that spans the combined StealC/Amadey and SocGholish actions).
Private-sector partners contributing technical analysis, statistics, C2 indicators, and encryption keys included ESET, Bitsight, Mitsui Bussan Secure Directions (MBSD), IBM X-Force, Proofpoint, Lumen, Infoblox, Orange Cyberdefense, Shadowserver, Have I Been Pwned, and Spamhaus. This is the latest in the Operation Endgame series, which has previously targeted DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader infrastructure; the June 24 action against Amadey and StealC is notable as the first Operation Endgame court filing to name multiple, previously distinct malware toolsets under a single RICO conspiracy theory, and as an early public example of AI-assisted (Copilot) malware code/infrastructure correlation directly cited in civil legal filings.
MITRE ATT&CK techniques used in TL-2026-1028
Collection
T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data; T1560 Archive Collected Data
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1614 System Location Discovery
defense-impairment
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Impact
T1486 Data Encrypted for Impact; T1496 Resource Hijacking
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
Affected products and versions in Microsoft AI-Assisted Investigation Links StealC and Amadey
- N/A (criminal MaaS platform) — Amadey botnet/loader
Vulnerable versions: Amadey v5 - N/A (criminal MaaS platform) — StealC infostealer
Vulnerable versions: StealC v2.2.4; StealC v2.22.0 - Microsoft Windows — Windows (all supported desktop versions)
Vulnerable versions: Any Windows host executing Amadey/StealC payloads
Remediation for Microsoft AI-Assisted Investigation Links StealC and Amadey
Patches
- Not applicable -- Amadey and StealC are criminal MaaS tooling, not vulnerable software; the disclosed PHP directory-traversal bug in the shared C2 panel backend was patched by the malware developers themselves in February 2026 and is not user-remediable
Immediate actions
- Block and monitor for known Amadey and StealC C2 domains/IPs published in Bitsight, ESET, and Shadowserver indicator feeds
- Hunt for SmokeLoader-delivered Amadey infections originating from cracked/pirated software downloads
- Hunt for ClickFix-style social-engineering lures (fake CAPTCHA/verification prompts instructing users to run PowerShell) associated with StealC delivery
- Force credential resets and session/token invalidation for any host with confirmed StealC or Amadey execution, given large-scale credential theft (browsers, email, FTP, crypto wallets)
- Inspect hosts with StealC infections for secondary payloads (AsyncRAT, HijackLoader, LockBit Black, RedLine, SDBbot, SectopRAT, SmokeLoader, TinyNuke, Vidar, XMRig, XTinyLoader, zgRAT) delivered via the StealC loader function
- Freeze/flag outbound cryptocurrency transactions to wallets associated with the disrupted infrastructure per law-enforcement indicator sharing
Workarounds
- Restrict or monitor use of Run/RunOnce and Scheduled Task registry persistence locations commonly abused by Amadey for persistence
- Educate users on ClickFix-style lures instructing manual execution of clipboard-pasted PowerShell/mshta commands
- Block execution of cracked-software installers and torrent-sourced executables at the endpoint via policy
Longer-term hardening
- Deploy application allowlisting / restrict execution of unsigned binaries from user-writable download and temp directories to blunt cracked-software and malvertising delivery vectors
- Implement browser credential-storage hardening (Application-Bound Encryption / OS-level credential vaulting) to reduce infostealer yield from browser data stores
- Deploy EDR behavioral detections for RC4-encrypted HTTP POST exfiltration patterns and JSON-based C2 beaconing consistent with StealC v2
- Build detection coverage for Operation Endgame-adjacent loader chains (SmokeLoader to Amadey, StealC to XTinyLoader to ransomware) given demonstrated ransomware handoff
- Track law-enforcement and vendor indicator-sharing feeds (ESET, Bitsight, Shadowserver, Spamhaus, Have I Been Pwned) for updated Amadey/StealC infrastructure as affiliates rebuild
Weaknesses (CWE) in Microsoft AI-Assisted Investigation Links StealC and Amadey
Timeline of Microsoft AI-Assisted Investigation Links StealC and Amadey
- Amadey first emerges as a Windows botnet/loader sold on underground forums, developed by an actor using the handle '_InCrease_'.
- StealC infostealer first appears on dark web marketplaces, developed and sold by an actor using the handle 'plymouth'.
- Proofpoint/IBM X-Force log analysis of a January 2025 StealC sample set identifies roughly 5,000 distinct victim machines.
- StealC v2 is released, introducing a JSON-based C2 protocol, redesigned web panel with integrated builder, multi-monitor screenshot capture, and a unified file grabber.
- A directory-traversal vulnerability (CWE-22) in the shared PHP-based C2 panel backend, which had allowed web-shell upload, is patched by the malware developers.
- Microsoft observes 140,000+ computers infected by Amadey and/or StealC in the first two weeks of May 2026 alone.
- Operation Endgame partners announce disruption of SocGholish (FakeUpdates) infrastructure affecting nearly 15,000 compromised websites, a precursor action to the Amadey/StealC takedown.
- ESET, Bitsight, IBM X-Force, and Proofpoint publish independent technical analyses and indicator sets supporting the takedown, sharing three years of tracking data (Q4 2025-H1 2026) and C2 configuration data.
- Microsoft DCU, Europol, Eurojust, and international law enforcement publicly announce the coordinated takedown of Amadey and StealC infrastructure (326 servers, 142 domains) as part of Operation Endgame; Microsoft files a civil RICO lawsuit against five defendants in the U.S. District Court for the Southern District of Florida (Case No. 26-cv-24064-JB).
- Proofpoint and IBM X-Force publish joint analysis 'StealC You Later' detailing the malware delivery chain, including the StealC-to-XTinyLoader-to-LockBit-Black ransomware handoff.
- Continued industry and media coverage (Security MEA, Infosecurity Magazine, CyberScoop) analyzes the legal significance of treating two independently developed malware families as a single RICO conspiracy.
Sources cited for Microsoft AI-Assisted Investigation Links StealC and Amadey
- Microsoft uses AI to link two malware operations in racketeering suit
- StealC you later: Proofpoint and IBM X-Force support Operation Endgame disruptions
- StealC You Later: Proofpoint and IBM X-Force Support Operation Endgame Disruptions
- Microsoft, Europol lead global takedown of infostealer malware
- Law enforcement hits StealC and Amadey malware networks
- Operation Endgame Takes Down StealC and Amadey Infostealers
- Bitsight Aids Disruption Efforts on Amadey & StealC Malware
- Amadey, StealC malware operations disrupted in Operation Endgame action
- $47M in Crypto Frozen in Global Infostealer Takedown: Europol
- In a first, a court takedown goes after two cybercrime tools at once
- ESET takes part in Operation Endgame to disrupt Amadey and Stealc
- ESET takes part in global Operation Endgame to disrupt Amadey botnet and Stealc infostealer
- Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks
- StealC infrastructure takedown assisted by AI analysis, C2 infiltration
- Amadey, Software S1025
Detection coverage for TL-2026-1028
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1028 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.