INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Operation Endgame Disrupts Malware Network Linked to Ransomware Gang

| 2026-06-24 14:35 CRITICAL HIGH
Executive Summary AI-generated
The international operation to take down the StealC malware infrastructure has been a long-running effort, announced on June 24 as part of Operation Endgame. Since January 2023, StealC has been an active malware-as-a-service tool used in cybercrime, designed to steal browser passwords, cookies, autofill data and credentials from various platforms including Telegram, Discord, Outlook, FileZilla, WinSCP, OpenVPN, ProtonVPN, and gaming platforms. Europol coordinated with international agencies such as ProofPoint and IBM X-Force to disrupt the operation affecting 66 domains and 296 servers linked to Amadey and StealC, resulting in over 25.6 million unique stolen credentials taken from compromised systems.
Technical Mitigations AI-generated
• Secure Command-Line Arguments: Implementing secure command-line arguments can prevent malware like StealC from delivering payloads to infected machines. This involves validating and sanitizing user input, using environment variables instead of hardcoded commands, and limiting the number of possible arguments. • Regularly Update Software and Systems: Keeping software and systems up-to-date with the latest security patches is crucial in preventing exploitation by malware like Amadey and StealC. Regular updates ensure that known vulnerabilities are patched before they can be used to gain unauthorized access or deliver payloads. • Implement Network Segmentation: Segmenting networks into smaller, isolated areas ( VLANs ) can limit the spread of malware like StealC and Amadey by making it more difficult for attackers to move laterally within a network. This approach also enables better monitoring and incident response. • Use Secure File Systems and Storage: Utilizing secure file systems and storage solutions, such as encrypted volumes or cloud-based services with robust security features (e.g., encryption at rest), can protect sensitive data from being accessed by malware like StealC and Amadey.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation EndgameOperation EndgameOperation Endgame DisruptsOperation Endgame Disrupts BumblebeeBumblebeeSocGholishSocGholishLockBit BlackLockBit BlackFakeUpdatesFakeUpdatesAmadeyAmadeyLockBit 3.0LockBit 3.0
Target & Sectors
DACH DACH NORDICS NORDICS BENELUX BENELUX NORTH_AMERICA NORTH_AMERICA healthcarehealthcare
Incident Timeline
‎January 2023
Threat actors used malware-as-a-service (MaaS) tool StealC to disrupt Amadey, a ransomware operation.
‎the first two weeks of May 2026
The incident involved approximately 140,000 infected devices.
infrastructure 140,000 infected devices
‎May 2026
Threat actors used a malware called StealC to target 200 malicious domains and nearly 200 active command-and-control servers.
infrastructure 200 malicious domains
infrastructure 50 domains
organisation EDR
‎June 18
The Dutch police took action to disrupt the Amadey, StealC malware operations and dismantle its botnet.
target_region Netherlands
tactic Botnet
malware SocGholish
general_metric 15,000 websites
‎24 June 2026
Threat actors used malware to target the Operation Endgame entities.
campaign Operation Endgame
‎2026/06/24
The Amadey and StealC malware operations were disrupted in Operation Endgame action.
organisation Maikel Rollman
organisation the Netherlands National High Tech Crime Unit (
organisation Operation Endgame
organisation Microsoft
organisation Europol
organisation Digital Crimes Unit
organisation IP
infrastructure 200 malicious domains
infrastructure 66 domains
infrastructure 296 servers
data_breach 25.6 unique stolen credentials
infrastructure 326 servers
infrastructure 142 domains
data_breach 27 credentials
organisation Hackread.com
organisation Spamhaus
organisation The Shadowserver Foundation
organisation Eurojust
organisation WordPress
infrastructure 106 servers
organisation ESET
organisation IBM
organisation ClickFix
organisation TikTok
organisation FileFix
financial €41 Investigators
organisation Telegram
organisation FileZilla
organisation VirusTotal
organisation Cosoi
organisation Infoblox Threat Intel
organisation Enable multi‑factor
organisation Delete
organisation Keep
‎early 2026
Threat actors used a previously unknown vulnerability in the early 2026 timeframe to target Proofpoint and IBM X-Force.
Tactical Metrics
Metrics
infrastructure
200
Malicious Domains
Metrics
infrastructure
140,000
Infected Devices
Metrics
infrastructure
326
Servers
Metrics
infrastructure
142
Domains
Metrics
financial
41,000,000
Investigators
Metrics
data_breach
27,000,000
Credentials
Metrics
infrastructure
50
Domains
Metrics
infrastructure
66
Domains
Metrics
infrastructure
296
Servers
Metrics
data_breach
25,600,000
Unique Stolen Credentials
Metrics
infrastructure
106
Servers