惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
罗磊的独立博客
爱范儿
爱范儿
J
Java Code Geeks
博客园 - 司徒正美
N
Netflix TechBlog - Medium
Microsoft Security Blog
Microsoft Security Blog
美团技术团队
小众软件
小众软件
Google DeepMind News
Google DeepMind News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
V2EX
博客园 - 聂微东
云风的 BLOG
云风的 BLOG
WordPress大学
WordPress大学
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Jina AI
Jina AI
Y
Y Combinator Blog
博客园 - 叶小钗
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
Vercel News
Vercel News

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Authorities Disrupt Password-Stealing Malware StealC Infr...
Guru Baran · 2026-06-25 · via Cyber Security News

Europol and law enforcement partners across multiple countries have dealt a significant blow to the cybercriminal ecosystems powering StealC, Amadey, and SocGholish malware, three widely deployed tools in the modern “cybercrime-as-a-service” supply chain.

Announced as part of Operation Endgame, the coordinated action dismantled key infrastructure enabling ransomware deployment, credential theft, and large-scale financial fraud.

Spanning two weeks of coordinated action, the operation involved law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States, alongside Europol, Eurojust, and private sector partners including Microsoft, Proofpoint, IBM X-Force, Bitdefender, and Shadowserver.

The combined effort targeted the criminal “assembly lines” that allow cyberattacks to scale globally.

Key outcomes of the operation include:

  • 326 servers and 142 domains were taken down, crippling malware distribution networks.
  • EUR 41 million (≈ USD 47 million) in crypto assets of criminal origin identified and frozen.
  • 27 million stolen login credentials recovered.
  • 14,971 infected websites remediated, including small businesses, restaurants, and auto repair shops.

Password-Stealing Malware StealC

StealC, classified as an infostealer with dropper functionality, was a primary target of this operation. Distributed through multiple attack vectors, StealC was engineered to silently extract passwords, stored access credentials, session tokens, and digital identities from compromised systems, feeding stolen data directly into underground marketplaces for fraud and resale.

Working in tandem with Amadey, a dropper/loader primarily spread through phishing campaigns, the two malware families formed a critical link in the cybercrime supply chain.

Amadey establishes initial access on a victim’s device, while StealC executes credential harvesting in the background. According to Microsoft’s threat intelligence, in just the first two weeks of May 2026, Amadey and StealC were collectively linked to over 140,000 infected computers worldwide.

SocGholish and the Evil Corp Connection

SocGholish, a dropper/loader distributed through fake browser update pop-ups on compromised WordPress sites, rounded out the trio of neutralized malware.

The malware is attributed to Evil Corp, the Russian cybercriminal group previously responsible for Zeus and Dridex, and associated with numerous ransomware and money-laundering operations.

Dutch Police have already patched vulnerabilities on infected sites and notified affected owners. WordPress administrators are urged to immediately change login credentials, enable multi-factor authentication, remove unknown admin accounts, and keep their platforms updated.

To avoid SocGholish infection, users should never act on browser pop-up update prompts and should only apply updates through official system settings or verified app stores.

Operation Endgame represents a strategic evolution in law enforcement’s approach to cybercrime, moving beyond individual threat actors to dismantle the broader infrastructure enabling attacks at scale.

Europol’s European Cybercrime Center (EC3) provided analytical support, crypto tracing, and victim notifications via platforms like HaveIBeenPwned, Spamhaus, and Shadowserver. The Joint Cybercrime Action Taskforce (J-CAT) aligned national investigations under a unified framework.

Victim notifications are being distributed through HaveIBeenPwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.

Operation Endgame remains the largest international operation ever undertaken against ransomware enablers, with more than 30 public and private partners actively supporting ongoing actions.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Guru Baran

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.