Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A)

Operation Endgame Disrupts Amadey Loader and StealC (TL-2026-1033), also tracked as Operation Endgame June 2026 Amadey/StealC Takedown, is a high-severity malware campaign, first published 2026-07-01. It is attributed to InCrease with medium confidence, affects Microsoft Windows (all consumer/enterprise desktop editions), maps to 32 MITRE ATT&CK techniques (T1005, T1016, T1021), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1033

Threat ID
TL-2026-1033
Also known as
Operation Endgame June 2026 Amadey/StealC Takedown
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-01
Last reviewed
2026-07-01
Attribution
InCrease
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
consumer, government administration, military, finance, technology, retail
Target regions
Global, india, united states of america, poland, italy, ukraine
Detection rules
9
Indicators of compromise
27

Malware and tooling in Operation Endgame Disrupts Amadey Loader and StealC

Malware and tooling: Amadey - S1025, Stealc, Amadey Builder v5.87, StealC Builder v2.2.4

On June 24, 2026, Microsoft's Digital Crimes Unit, Europol EC3, Bitsight TRACE, ESET, IBM X-Force, Proofpoint and law-enforcement partners across Belgium, Canada, Denmark, France, Germany, the Netherlands, the UK and the US executed Operation Endgame actions (June 15-19, 2026) against the Amadey loader/botnet (operator alias "InCrease", active since October 2018) and the StealC information stealer (operator alias "plymouth", active since February 2023), seizing 47 domains and 182 C2 IPs (34 Amadey core C2, 69 Amadey task C2, 79 StealC C2) hosted on shared bulletproof infrastructure. The action recovered roughly 27 million stolen credentials from 385,000+ compromised systems, identified ~$47 million in criminal cryptocurrency, and was filed as a civil RICO complaint (Case No. 26-cv-24064-JB, U.S. District Court, Southern District of Florida).

How Operation Endgame Disrupts Amadey Loader and StealC works

Amadey is a C++ modular Windows loader/botnet sold as Malware-as-a-Service on Russian-language cybercrime forums (xss.is, exploit.in) since October 2018 by the actor "InCrease"; the current builder (v5.87) is priced at $600 per license plus $50 per rebuild. It fingerprints the host (OS, architecture, AV products, username, domain, hardware ID), persists via Registry Run/RunOnce keys and scheduled tasks, obfuscates strings and configuration with a Vigenère cipher layered under Base64, and communicates over plain HTTP to per-build hardcoded C2 URLs using structured POST tags (id, vs, sd, os, bi, ar). Its plugin architecture (loaded via rundll32.exe with a "Main" export) adds hVNC, a reverse proxy, a clipboard hijacker (clip64.dll), and a browser credential stealer (cred64.dll) covering Chrome, Firefox, Opera and 10+ other browsers. Amadey is itself frequently used as an initial-access/loader stage to deliver Lumma Stealer, StealC, ransomware affiliates, and — per Microsoft's December 2024 reporting — the Russian FSB-linked APT Secret Blizzard (Turla/Snake/Uroburos), which rode Amadey's MaaS panels to deploy PowerShell droppers and the KazuarV2 backdoor against Ukrainian front-line military systems using STARLINK connectivity between March and April 2024.

StealC, advertised since February 2023 by the actor "plymouth" ($300/month, $700/3-months, $1,000/6-months), is a C++ information stealer with two lineages: v1 (x86, WinINet transport) and v2 (x64, WinHTTP transport, JSON-over-Base64 C2 protocol, released March 2025, current build v2.2.1/v2.2.4). It targets 23+ browsers, 100+ browser extensions, 15+ desktop cryptocurrency wallets, and application data from Discord, FileZilla, Outlook, Steam and Telegram, encrypting strings and C2 traffic with per-sample RC4 keys. Both families implement CIS-country execution guardrails, exiting when the host keyboard layout or UI locale matches Russia, Ukraine, Belarus or Kazakhstan. Distribution is via trojanized/cracked software installers, fake updates, pay-per-install (PPI) affiliate networks, and Amadey itself acting as a secondary loader for StealC.

Operation Endgame's June 2026 action addressed shared bulletproof-hosting infrastructure operated by ELITETEAM (AS56873, Seychelles), Chang Way Technologies (AS59425) and Femo IT Solutions (AS214351). Microsoft's civil complaint independently flagged 200+ malicious C2 domains/IPs and severed 18,000 victim machines from criminal control; ESET separately measured ~50 affected domains and ~200 active C2 servers across 53 distinct Amadey clusters and 73 distinct StealC clusters. Telemetry cited in the disclosures shows roughly 200,000 distinct Amadey-infected IPs sinkholed over a 90-day window (India highest concentration) and 140,000+ combined Amadey/StealC infections in the first two weeks of May 2026 alone (US, Poland and Italy leading StealC infection counts). Community indicator sharing tied to the action included 14,000+ samples to MalwareBazaar, 4,000+ URLs to URLhaus, and 1,800+ indicators to ThreatFox, alongside published YARA/Suricata detection content.

MITRE ATT&CK techniques used in TL-2026-1033

Collection

T1005 Data from Local System; T1115 Clipboard Data

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery; T1614 System Location Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1129 Shared Modules

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution; T1573 Encrypted Channel

defense-impairment

T1112 Modify Registry; T1222 File and Directory Permissions Modification; T1553 Subvert Trust Controls

Initial Access

T1195 Supply Chain Compromise

execution

T1204 User Execution

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Resource Development

T1588 Obtain Capabilities

Affected products and versions in Operation Endgame Disrupts Amadey Loader and StealC

  • Microsoft — Windows (all consumer/enterprise desktop editions)
    Vulnerable versions: Windows 10; Windows 11; Windows Server

Remediation for Operation Endgame Disrupts Amadey Loader and StealC

Immediate actions

  • Block the published Amadey/StealC C2 IPs and domains (mi.overlapsnowbound.com, 62.60.226.159, 64.188.91.237, 176.111.174.140, 158.94.208.130) at perimeter and DNS resolvers
  • Hunt for Registry Run/RunOnce and User Shell Folders keys pointing at %temp% subfolders, and for unexpected scheduled tasks created by non-admin users
  • Force credential resets and session/cookie invalidation for any host with confirmed Amadey/StealC execution given the 27M recovered credentials tied to this campaign
  • Audit for rundll32.exe invocations with a "Main" export parameter and for clip64.dll/cred64.dll-style plugin loads

Workarounds

  • Disable execution of Rundll32 with attacker-controlled DLL/export arguments via WDAC or AppLocker policy
  • Restrict outbound HTTP to raw IP-literal destinations and non-standard ports at the egress proxy

Longer-term hardening

  • Deploy EDR behavioral detections for Vigenère/Base64 and RC4-obfuscated HTTP POST beacons with structured short-tag parameters
  • Restrict execution of unsigned installers from cracked-software/PPI download sources via application control
  • Monitor for CIS-keyboard-layout execution-guardrail patterns as a stealer/loader detection heuristic
  • Correlate any Amadey execution on government, defense, or critical-infrastructure endpoints against known re-use by state-sponsored actors (e.g., Secret Blizzard/Turla)

Timeline of Operation Endgame Disrupts Amadey Loader and StealC

  • Amadey loader/botnet first advertised on Russian-language cybercrime forums by the actor 'InCrease'
  • StealC information stealer first advertised on xss.is/exploit.in by the actor 'plymouth'
  • Russian FSB-linked Secret Blizzard (Turla) begins leveraging Amadey MaaS panels to deliver PowerShell droppers and the KazuarV2 backdoor against Ukrainian front-line military systems using STARLINK connectivity
  • StealC v2 released with a redesigned x64/WinHTTP architecture, JSON-over-Base64 C2 protocol, and CIS-locale execution guardrail
  • Microsoft telemetry records 140,000+ combined Amadey/StealC infected devices worldwide in a two-week window
  • Coordinated multi-agency Operation Endgame takedown actions begin against Amadey/StealC infrastructure
  • Takedown operations conclude: 47 domains and 182 C2 IPs (326 servers, 142 domains per follow-up reporting) seized across shared bulletproof-hosting infrastructure
  • Europol, Microsoft, Bitsight TRACE and ESET publicly disclose the Operation Endgame action and publish IOCs, YARA and Suricata rules
  • Microsoft Digital Crimes Unit files civil RICO complaint (Case No. 26-cv-24064-JB) in the U.S. District Court, Southern District of Florida
  • Industry press (SecurityMEA and others) publish follow-up analysis on the scale and scope of the takedown

Sources cited for Operation Endgame Disrupts Amadey Loader and StealC

Threats related to Operation Endgame Disrupts Amadey Loader and StealC

Detection coverage for TL-2026-1033

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1033 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats