惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
IT之家
IT之家
Google DeepMind News
Google DeepMind News
D
Docker
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
博客园 - Franky
月光博客
月光博客
宝玉的分享
宝玉的分享
酷 壳 – CoolShell
酷 壳 – CoolShell
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
Law enforcement hits StealC and Amadey malware networks -...
Zeljka Zorz · 2026-06-24 · via Help Net Security

Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey.

StealC Amadey malware disrupted

The notice on disrupted websites (Source: Microsoft)

While developed by separate criminal groups, those two malware families work in tandem to compromise devices and harvest sensitive data. Law enforcement and private sector partners, including Microsoft and Proofpoint, coordinated action against the infrastructure delivering both threats.

Infrastructure dismantled, millions in crypto seized

On 18 June 2026, law enforcement agencies from the Netherlands, Canada, the United States, and Germany, supported by Europol and Eurojust, announced the successful disruption of the infrastructure behind the SocGholish malware framework. Worldwide, 106 servers and domains were taken down and nearly 15,000 compromised websites were remediated.

Today, a follow-up action targeting StealC and Amadey was announced.

“During this action, 326 servers and 142 domains were actioned by law enforcement and the private sector partners, severely crippling the malware’s distribution network,” Europol stated.

Law enforcement has also managed to identify and freeze over 41 million euros (approximately 47 million US dollars) in related crypto assets.

Additionally, Microsoft’s Digital Crimes Unit filed a lawsuit against multiple alleged enablers involved in StealC and Amadey and took down associated infrastructure.

These individuals include Amadey and StealC malware-as-a-service operators, as well as affiliates.

Microsoft targets operators and affiliates

“Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information,” noted Steven Masada, Assistant General Counsel with Microsoft’s Digital Crimes Unit.

According to data collected by the company in the first two weeks of May 2026, Amadey and StealC were linked to 140,000+ infected computers worldwide.

With the help of AI, investigators were able to discover that even though the two threats were developed by separate cybercriminals, they relied on the same infrastructure.

“Those insights allowed the legal team to treat both malware families as part of a single conspiracy. Instead of going after each tool separately, as we have done in the past, we used [the Racketeer Influenced and Corrupt Organizations Act (RICO)] to charge multiple complicit enablers involved across the operation,” Masada added.

He also shared that Microsoft pinpointed over 18,000 victim computers, has severed criminal control of those devices, and is helping telecoms protect affected customers.

How researchers cracked StealC

Proofpoint and IBM X-Force researchers revealed today their part in the operation.

They identified a vulnerability in the StealC C2 panel, which was exploited to help with the disruption operation, and they extracted configurations from many StealC samples.

These configurations contained URLs used to connect to and communicate with the C2 panel, campaign and affiliate IDs, unique client/bot IDs, and C2 communication encryption keys, and were used to track StealC operations and affiliate groups.

They also built a StealC bot emulator, which allowed them to simulate the network activity that occurs in a normal StealC infection, and retrieve and analyze the additional malicious payloads that criminals delivered via this infostealer-cum-dropper.

“In some cases, the StealC client was delivered only one payload, such as another stealer or a remote access trojan (RAT). In many cases, however, the StealC client received another loader malware, which subsequently downloaded the final payload,” the researchers shared.

In one case, StealC downloaded XTinyLoader, which then downloaded a LockBit Black ransomware payload.

Microsoft’s threat analysts also detailed the two Malware-as-a-service operations and shared indicators of compromise pointing to Amadey and StealC infections.

Compromised credentials

According to Europol, nearly 27 million stolen login credentials have been tracked down as part of this operation.

Following the SocGholish infrastructure disruption, compromised credentials have been added to the Have I Been Pwned database, allowing users check whether theirs are among those.

It’s currently unclear whether the same will happen with the latest batch.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!