# Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame)

> Microsoft's Digital Crimes Unit used Copilot and other AI tools to accelerate malware code and infrastructure analysis, linking the StealC infostealer and Amadey MaaS loader as a single criminal enterprise and underpinning a civil RICO suit against five defendants. Coordinated with Europol/Eurojust as part of Operation Endgame, the action disrupted 326 servers and 142 domains, recovered ~27 million stolen credentials from 385,000+ compromised systems, and froze roughly $47 million (€41M) in cryptocurrency.

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-07-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1028
- **ID:** TL-2026-1028
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Amadey
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On June 24, 2026, Microsoft's Digital Crimes Unit (DCU), together with Europol's European Cybercrime Centre (EC3), Eurojust, Germany's Federal Criminal Police Office (BKA), and law enforcement in Canada, Denmark, the Netherlands, the United Kingdom, and the United States, announced a coordinated disruption of infrastructure supporting the StealC infostealer and the Amadey malware-as-a-service (MaaS) loader as part of the ongoing Operation Endgame initiative. The action followed a related June 18, 2026 disruption of SocGholish (FakeUpdates) infrastructure affecting nearly 15,000 compromised websites.

Microsoft's legal filing, lodged in the U.S. District Court for the Southern District of Florida (Case No. 26-cv-24064-JB), treats Amadey and StealC as components of a single conspiracy under the civil Racketeer Influenced and Corrupt Organizations (RICO) Act, naming five defendants. Steven Masada, assistant general counsel for Microsoft's DCU, said the two malware families were previously tracked as unrelated but AI-assisted analysis using Copilot and related tooling let investigators 'ask questions in plain English instead of manually combing through complex code,' compressing analysis that would normally take 'hours or days into minutes' and surfacing shared C2 infrastructure, encryption keys, campaign/affiliate identifiers, and operational overlap between the two toolsets.

Amadey has operated as a modular Windows malware loader and botnet client since 2018, sold by an actor using the handle '_InCrease_' for roughly $600 in Bitcoin per license plus a $50 rebuild fee. It is typically distributed via SmokeLoader campaigns bundled with cracked/pirated software, and offers plugins for clipboard monitoring/clipping, credential theft, hVNC-based remote access, and generic payload delivery (stealers, cryptominers, RATs, ransomware) to affiliate operators of varying skill levels.

StealC, active since January 2023 and sold by an actor using the handle 'plymouth,' is a C++ information stealer offered as a subscription (roughly $280-$1,000 for one to six months). StealC v2 (current build tracked at v2.22.0/v2.2.4) introduced a streamlined JSON-based C2 protocol, a redesigned web panel with an integrated builder, multi-monitor screenshot capture, a unified file grabber, and an optional loader function allowing operators to specify secondary payload URLs from the C2 panel. It targets credentials and session data from 23+ browsers, 100+ browser extensions, 15+ desktop cryptocurrency wallets, email and FTP clients, gaming platforms, and messaging applications. Victims beacon to StealC C2 servers with 'create' requests to obtain access tokens, then exfiltrate stolen data via 'upload_file' requests carrying RC4-encrypted, Base64-encoded JSON payloads. StealC has been used as a first-stage dropper delivering secondary payloads including Amadey, AsyncRAT, HijackLoader, LockBit Black ransomware, MaskGramStealer, RedLine Stealer, SDBbot, SectopRAT, SmokeLoader, SVCStealer, TinyNuke, Vidar, XMRig, XTinyLoader, and zgRAT/Python-based stealers and crypto clippers -- in one documented chain, StealC delivered XTinyLoader, which in turn deployed LockBit Black ransomware.

Both MaaS platforms use a self-hosted administration-panel model requiring affiliates to run their own backend infrastructure, giving affiliates direct control of victim data and payload distribution while complicating centralized takedown. Investigators (including ESET, which supplied three years of tracking data spanning Q4 2025-H1 2026) identified a directory-traversal vulnerability in the PHP backend of the shared C2 panel software that allowed web-shell upload onto C2 servers, patched by the malware developers in February 2026 -- a bug that assisted defenders' infrastructure mapping.

Disruption metrics reported across partners (figures vary slightly by source and reporting window): 326 servers and 142 domains taken down/seized per Europol; roughly 200 active C2 servers and ~50 domains reported by ESET; Bitsight independently identified 182 combined C2 infrastructure points (47 domains, 34 Amadey core C2 IPs, 69 Amadey task C2 IPs, 79 StealC IPs); Proofpoint/IBM X-Force cited 66 domains and 296 servers. Amadey sinkhole telemetry over a 90-day window logged roughly 200,000 infected IPs, concentrated in India; StealC log analysis from a January 2025 sample set identified roughly 5,000 victim machines. Microsoft reported 140,000+ infected computers linked to the two malware families in the first two weeks of May 2026 alone, and separately identified and severed criminal control over 18,000+ victim computers. Approximately 27 million stolen credentials were recovered from more than 385,000 compromised systems. Investigators identified and froze roughly €41 million (~$47 million) in cryptocurrency assets linked to the criminal enterprise (a figure that spans the combined StealC/Amadey and SocGholish actions).

Private-sector partners contributing technical analysis, statistics, C2 indicators, and encryption keys included ESET, Bitsight, Mitsui Bussan Secure Directions (MBSD), IBM X-Force, Proofpoint, Lumen, Infoblox, Orange Cyberdefense, Shadowserver, Have I Been Pwned, and Spamhaus. This is the latest in the Operation Endgame series, which has previously targeted DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader infrastructure; the June 24 action against Amadey and StealC is notable as the first Operation Endgame court filing to name multiple, previously distinct malware toolsets under a single RICO conspiracy theory, and as an early public example of AI-assisted (Copilot) malware code/infrastructure correlation directly cited in civil legal filings.

## MITRE ATT&CK

- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1566 Phishing
- T1189 Drive-by Compromise
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job
- T1112 Modify Registry
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1552 Unsecured Credentials
- T1614 System Location Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1115 Clipboard Data
- T1113 Screen Capture
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1496 Resource Hijacking
- T1021 Remote Services

## Sources

- [Microsoft uses AI to link two malware operations in racketeering suit](https://www.theregister.com/security/2026/06/24/microsoft-uses-ai-to-link-two-malware-operations-in-racketeering-suit/5261656)
- [StealC you later: Proofpoint and IBM X-Force support Operation Endgame disruptions](https://www.ibm.com/think/x-force/stealc-you-later-proofpoint-x-force-support-operation-endgame-disruptions)
- [StealC You Later: Proofpoint and IBM X-Force Support Operation Endgame Disruptions](https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame)
- [Microsoft, Europol lead global takedown of infostealer malware](https://www.cybersecuritydive.com/news/microsoft-europol-international-takedown-infostealer-malware/823655/)
- [Law enforcement hits StealC and Amadey malware networks](https://www.helpnetsecurity.com/2026/06/24/operation-endgame-stealc-amadey-malware-disrupted/)
- [Operation Endgame Takes Down StealC and Amadey Infostealers](https://www.infosecurity-magazine.com/news/operation-endgame-stealc-amadey/)
- [Bitsight Aids Disruption Efforts on Amadey & StealC Malware](https://www.bitsight.com/blog/bitsight-aids-disruption-efforts-on-amadey-malware-and-stealc-malware)
- [Amadey, StealC malware operations disrupted in Operation Endgame action](https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/)
- [$47M in Crypto Frozen in Global Infostealer Takedown: Europol](https://decrypt.co/372071/47m-in-crypto-frozen-in-global-infostealer-takedown-europol)
- [In a first, a court takedown goes after two cybercrime tools at once](https://cyberscoop.com/microsoft-amadey-stealc-takedown/)
- [ESET takes part in Operation Endgame to disrupt Amadey and Stealc](https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/)
- [ESET takes part in global Operation Endgame to disrupt Amadey botnet and Stealc infostealer](https://www.eset.com/us/about/newsroom/research/eset-takes-part-in-operation-endgame-disrupt-amadey-botnet-and-stealc-infostealer/)
- [Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks](https://hackread.com/operation-endgame-stealc-amadey-socgholish-malware/)
- [StealC infrastructure takedown assisted by AI analysis, C2 infiltration](https://www.scworld.com/news/stealc-infrastructure-takedown-assisted-by-ai-analysis-c2-infiltration)
- [Amadey, Software S1025](https://attack.mitre.org/software/S1025/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1028
