INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Europol Disrupts SocGholish Servers, Cleans Malicious TDS Threat

| 2026-06-24 18:43 CRITICAL HIGH
Executive Summary AI-generated
Europol's Operation Endgame has disrupted the infrastructure behind three major malware families: SocGholish, Amadey, and StealC. These cybercrime groups have been linked to various high-profile ransomware attacks, including Zeus and Dridex, and are responsible for significant financial losses and damage to critical infrastructure worldwide. By targeting the initial access malware used in these infections, Europol has effectively crippled the ability of these groups to launch their operations. The operation's strategic significance lies in its simultaneous targeting of SocGholish, Amadey, and StealC families, which together form the opening stages of a cybercrime attack chain. This has resulted in significant disruptions to online services, including 14,971 infected websites across various sectors, making it one of the largest international operations ever undertaken against ransomware enablers worldwide.
Technical Mitigations AI-generated
• The operation targeted the infrastructure behind SocGholish, Amadey, and StealC malware families, disrupting their ability to launch ransomware, financial fraud, and attacks on critical infrastructure. • Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK, and the US, alongside private firms like Microsoft, Bitdefender, IBM X-Force, Proofpoint, Infoblox, Shadowserver, Orange Cyberdefense, and other partners.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation EndgameOperation EndgameOperation Endgame DisruptsOperation Endgame DisruptsOperation Endgame OperationOperation Endgame OperationOperation RiptideOperation Riptide Indrik SpiderIndrik SpiderMustard TempestMustard Tempest SystemBCSystemBCAzorultAzorultIcedIDIcedIDRansomHubRansomHubDridexDridexPikabotPikabotBumblebeeBumblebeeSocGholishSocGholishWastedLockerWastedLockerFakeUpdatesFakeUpdatesRaspberry RobinRaspberry RobinAmadeyAmadey
Target & Sectors
BENELUX BENELUX NORTH_AMERICA NORTH_AMERICA ASEAN ASEAN DACH DACH NORDICS NORDICS retailretail governmentgovernment technologytechnology legallegal educationeducation healthcarehealthcare transportationtransportation
Incident Timeline
‎at least 2017
Threat actors used SocGholish to disrupt the StealC and Amadey Malware infrastructure in Operation Endgame.
malware SocGholish
organisation WordPress
tactic T1059.007 - JavaScript
malware FakeUpdates
organisation GhoLoader
‎October 2018
Threat actors used Amadey malware to disrupt the infrastructure of StealC and Amadey Malware.
malware Amadey
tactic Phishing
‎Between June 15 and 19, 2026
Threat actors used Europol's law enforcement operation to disrupt the StealC and Amadey Malware infrastructure in Operation Endgame.
target_region Canada
target_region Denmark
target_region Germany
target_region Netherlands
target_region United Kingdom
target_region United States
attribution Europol
attribution Microsoft
attribution IBM
attribution Infoblox, Shadowserver
‎January 2023
Threat actors used Amadey Malware to target devices and StealC, a harvesting layer, to extract passwords and sensitive data from compromised machines.
‎May 2024
Threat actors used Europol to disrupt the StealC and Amadey Malware infrastructure in Operation Endgame.
infrastructure 100 servers
malware IcedID
malware SystemBC
malware Pikabot
malware Bumblebee
organisation DanaBot
general_metric 16 people
‎May 2025
Threat actors used Europol to disrupt the StealC and Amadey Malware infrastructure in Operation Endgame.
infrastructure 100 servers
malware IcedID
malware SystemBC
malware Pikabot
malware Bumblebee
organisation DanaBot
general_metric 16 people
‎2025/06/19
SocGholish infected compromised websites through Silent Push infections.
malware SocGholish
‎November 2025
Arctic Wolf revealed that SocGholish was used by the RomCom threat actors to deliver Mythic Agent, disrupting the StealC and Amadey malware infrastructure.
malware SocGholish
organisation RomCom
tactic Botnet
infrastructure 1,025 servers
‎January 2026
Threat actors used Europol's cyber operations to disrupt the StealC and Amadey malware infrastructure.
target_region Netherlands
attribution Amsterdam’s
‎just the first two weeks of May 2026
Microsoft's systems were compromised, infecting over 140,000 computers worldwide.
organisation Microsoft
general_metric 140,000 infected computers
‎May 2026
Threat actors used Europol's tools to disrupt the StealC and Amadey malware infrastructure.
organisation EUROPOL
organisation SecurityAffairs
organisation EuroJust
organisation DIVD
organisation Spamhaus
organisation CheckjeHack
organisation the Dutch National Cyber Security Centre
‎2026/06/16
Europol disrupted the stealC and amadey Malware's infrastructure in Operation Endgame.
malware SocGholish
‎June 18
Threat actors used the StealC and Amadey malware to disrupt Europol's infrastructure.
tactic Ransomware
tactic Botnet
tactic Espionage
attribution FBI Cyber Division
‎18 June 2026
Threat actors used Europol's operational support to disrupt the SocGholish malware framework.
malware SocGholish
campaign Operation Endgame
target_region Germany
target_region Netherlands
target_region United States
attribution Europol
attribution RCMP
attribution the US Federal Bureau of Investigation (FBI
attribution Federal Criminal Police Office
attribution BKA
‎2026/06/18
SocGholish's stealC and Amadey malware infrastructure was disrupted by Europol.
malware SocGholish
‎2026/06/24
SocGholish Disrupts Europol's StealC and Amadey Malware Infrastructure.
organisation EUROPOL
infrastructure 106 servers
organisation the Netherlands National High Tech Crime Unit
organisation Maikel Rollman
infrastructure 100 servers
organisation Evil Corp
organisation Evil Corp.
organisation Phoenix CryptoLocker
organisation creada
organisation Después de la infección
organisation los atacantes
organisation un grupo de ciberdelincuentes
organisation campañas de ransomware
organisation LockBit
organisation DoppelPaymer
organisation WastedLoocker
organisation DanaBot
organisation Trickbot, Smokeloader,
organisation WordPress
organisation TDS
organisation Keitaro
organisation IAM
organisation DEV-0243
threat_actor Indrik Spider
organisation UNC2165
organisation Orange Cyberdefense
organisation GhostWeaver
organisation NetSupport
organisation the Shadowserver Foundation
organisation el malware
organisation la red de
organisation Europol Disrupts
financial 153,527 breached accounts
organisation Hackread.com
infrastructure 1,000 servers
organisation Los
organisation EuroJust
organisation el apoyo de Europol
infrastructure 326 servers
infrastructure 142 domains
data_breach 27 stolen login credentials
financial €41 credentials
organisation TDSs
organisation Novo Nordisk Breach Highlights
organisation CMS
organisation Google Chrome
organisation Mozilla Firefox
organisation Gold Prelude
threat_actor Mustard Tempest
organisation Purple Vallhund
organisation DNS
organisation falsas actualizaciones de programas
organisation un
organisation El mensaje parecía real
organisation instalaciones sin actualizar
organisation el riesgo de nuevos
organisation las puertas traseras
organisation el ordenador de la víctima
organisation un pago
organisation La operación permitió retirar
organisation el malware siga
organisation Sin
organisation Cómo
organisation las cuentas de administrador que
organisation También
organisation los complementos
organisation GhoLoader
organisation JScript
organisation PHP
organisation EDR
Tactical Metrics
Metrics
infrastructure
326
Servers
Metrics
infrastructure
142
Domains
Metrics
data_breach
27,000,000
Stolen Login Credentials
Metrics
financial
41,000,000
Credentials
Metrics
infrastructure
106
Servers
Metrics
financial
153,527
Breached Accounts
Metrics
infrastructure
100
Servers
Metrics
infrastructure
1,025
Servers
Metrics
infrastructure
1,000
Servers