惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
博客园 - 司徒正美
A
About on SuperTechFans
Vercel News
Vercel News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
爱范儿
爱范儿
I
InfoQ
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
Google DeepMind News
Google DeepMind News
T
Tailwind CSS Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
F
Fortinet All Blogs
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
D
Docker
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
M
MIT News - Artificial intelligence
Jina AI
Jina AI
H
Help Net Security
量子位
IT之家
IT之家

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss
Operation Endgame deals fresh blow to StealC and Amadey m...
Vlad CONSTANTINESCU · 2026-06-25 · via Consumer Insights

International law enforcement and private-sector partners have disrupted infrastructure tied to StealC, Amadey and SocGholish—malware families used to enable ransomware attacks.

Key takeaways

  • Operation Endgame targeted infrastructure behind StealC, Amadey and SocGholish.
  • Authorities and private partners actioned 326 servers and 142 domains.
  • Investigators recovered roughly 27 million stolen login credentials.
  • More than €41 million in criminal crypto assets was identified and restricted.

A coordinated strike against malware supply chains

Europol, Eurojust and law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom and the United States have announced a new phase of Operation Endgame, this time targeting malware services that help cybercriminals scale attacks.

The action focused on the infrastructure behind SocGholish, Amadey and StealC—three malware families that often sit early in the attack chain. Rather than targeting only individual operators, the operation sought to disrupt the criminal “assembly lines” that feed credential theft, fraud and ransomware deployment.

Why StealC and Amadey matter

StealC is an infostealer built to harvest passwords, browser data, cryptocurrency wallet information and other sensitive details from infected devices. Stolen credentials can be sold, reused in account takeovers, or passed on to initial access brokers that serve ransomware groups.

Amadey plays a complementary role. It’s primarily a malware loader, giving attackers a foothold on compromised systems and allowing them to deploy additional payloads. Security researchers say both malware families have been offered through malware-as-a-service models, making them accessible to affiliates with varying levels of skill.

Disruption helps, but users remain exposed

The takedown affected hundreds of servers and domains, and the recovery of 27 million credentials shows the scale of the victim pool. However, infrastructure disruption does not automatically undo infections, reset stolen passwords, or prevent operators from rebuilding elsewhere.

Individuals should change exposed passwords, enable multi-factor authentication, use password managers like Bitdefender SecurePass to prevent password fatigue, avoid browser-stored credentials where possible, and treat fake updates, cracked software and suspicious “fix” instructions as signs of danger. Businesses should prioritize endpoint visibility, phishing-resistant authentication, rapid patching and detection for loaders, stealers and unusual credential use.

How to protect against infostealers and malware loaders

For home users, Bitdefender Ultimate Security adds multi-layered protection against malware, ransomware, scams and unsafe web activity, alongside VPN, password management and digital identity protection.