Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A) — Threadlinqs Intelligence
As of 2026-07-01, Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A) is a high-severity malware threat attributed to InCrease, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1033 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: InCrease · FINANCIAL
On June 24, 2026, Microsoft's Digital Crimes Unit, Europol EC3, Bitsight TRACE, ESET, IBM X-Force, Proofpoint and law-enforcement partners across Belgium, Canada, Denmark, France, Germany, the
Amadey is a C++ modular Windows loader/botnet sold as Malware-as-a-Service on Russian-language cybercrime forums (xss.is, exploit.in) since October 2018 by the actor "InCrease"; the current builder (v5.87) is priced at $600 per license plus $50 per rebuild. It fingerprints the host (OS, architecture, AV products, username, domain, hardware ID), persists via Registry Run/RunOnce keys and scheduled tasks, obfuscates strings and configuration with a Vigenère cipher layered under Base64, and communicates over plain HTTP to per-build hardcoded C2 URLs using structured POST tags (id, vs, sd, os, bi, ar). Its plugin architecture (loaded via rundll32.exe with a "Main" export) adds hVNC, a reverse proxy, a clipboard hijacker (clip64.dll), and a browser credential stealer (cred64.dll) covering Chrome, Firefox, Opera and 10+ other browsers. Amadey is itself frequently used as an initial-access/loader stage to deliver Lumma Stealer, StealC, ransomware affiliates, and — per Microsoft's December 2024 reporting — the Russian FSB-linked APT Secret Blizzard (Turla/Snake/Uroburos), which rode Amadey's MaaS panels to deploy PowerShell droppers and the KazuarV2 backdoor against Ukrainian front-line military systems using STARLINK connectivity between March and April 2024.
StealC, advertised since February 2023 by the actor "plymouth" ($300/month, $700/3-months, $1,000/6-months), is a C++ information stealer with two lineages: v1 (x86, WinINet transport) and v2 (x64, WinHTTP transport, JSON-over-Base64 C2 protocol, released March 2025, current build v2.2.1/v2.2.4). It targets 23+ browsers, 100+ browser extensions, 15+ desktop cryptocurrency wallets, and application data from Discord, FileZilla, Outlook, Steam and Telegram, encrypting strings and C2 traffic with per-sample RC4 keys. Both families implement CIS-country execution guardrails, exiting when the host keyboard layout or UI locale matches Russia, Ukraine, Belarus or Kazakhstan. Distribution is via trojanized/cracked software installers, fake updates, pay-per-install (PPI) affiliate networks, and Amadey itself acting as a secondary loader for StealC.
Operation Endgame's June 2026 action addressed shared bulletproof-hosting infrastructure operated by ELITETEAM (AS56873, Seychelles), Chang Way Technologies (AS59425) and Femo IT Solutions (AS214351). Microsoft's civil complaint independently flagged 200+ malicious C2 domains/IPs and severed 18,000 victim machines from criminal control; ESET separately measured ~50 affected domains and ~200 active C2 servers across 53 distinct Amadey clusters and 73 distinct StealC clusters. Telemetry cited in the disclosures shows roughly 200,000 distinct Amadey-infected IPs sinkholed over a 90-day window (India highest concentration) and 140,000+ combined Amadey/StealC infections in the first two weeks of May 2026 alone (US, Poland and Italy leading StealC infection counts). Community indicator sharing tied to the action included 14,000+ samples to MalwareBazaar, 4,000+ URLs to URLhaus, and 1,800+ indicators to ThreatFox, alongside published YARA/Suricata detection content.
Target sectors: consumer, government administration, military, finance, technology, retail
Target regions: Global, india, united states of america, poland, italy, ukraine
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1588, T1195, T1204, T1106, T1059, T1129, T1547, T1053, T1140, T1112