惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
Recent Announcements
Recent Announcements
B
Blog
D
Docker
V
V2EX
GbyAI
GbyAI
L
LangChain Blog
博客园 - Franky
U
Unit 42
T
The Blog of Author Tim Ferriss
A
About on SuperTechFans
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
博客园_首页
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
Y
Y Combinator Blog
量子位
Blog — PlanetScale
Blog — PlanetScale
罗磊的独立博客

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Law enforcement hits StealC and Amadey malware networks -...
Zeljka Zorz · 2026-06-24 · via Help Net Security

Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey.

StealC Amadey malware disrupted

The notice on disrupted websites (Source: Microsoft)

While developed by separate criminal groups, those two malware families work in tandem to compromise devices and harvest sensitive data. Law enforcement and private sector partners, including Microsoft and Proofpoint, coordinated action against the infrastructure delivering both threats.

Infrastructure dismantled, millions in crypto seized

On 18 June 2026, law enforcement agencies from the Netherlands, Canada, the United States, and Germany, supported by Europol and Eurojust, announced the successful disruption of the infrastructure behind the SocGholish malware framework. Worldwide, 106 servers and domains were taken down and nearly 15,000 compromised websites were remediated.

Today, a follow-up action targeting StealC and Amadey was announced.

“During this action, 326 servers and 142 domains were actioned by law enforcement and the private sector partners, severely crippling the malware’s distribution network,” Europol stated.

Law enforcement has also managed to identify and freeze over 41 million euros (approximately 47 million US dollars) in related crypto assets.

Additionally, Microsoft’s Digital Crimes Unit filed a lawsuit against multiple alleged enablers involved in StealC and Amadey and took down associated infrastructure.

These individuals include Amadey and StealC malware-as-a-service operators, as well as affiliates.

Microsoft targets operators and affiliates

“Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information,” noted Steven Masada, Assistant General Counsel with Microsoft’s Digital Crimes Unit.

According to data collected by the company in the first two weeks of May 2026, Amadey and StealC were linked to 140,000+ infected computers worldwide.

With the help of AI, investigators were able to discover that even though the two threats were developed by separate cybercriminals, they relied on the same infrastructure.

“Those insights allowed the legal team to treat both malware families as part of a single conspiracy. Instead of going after each tool separately, as we have done in the past, we used [the Racketeer Influenced and Corrupt Organizations Act (RICO)] to charge multiple complicit enablers involved across the operation,” Masada added.

He also shared that Microsoft pinpointed over 18,000 victim computers, has severed criminal control of those devices, and is helping telecoms protect affected customers.

How researchers cracked StealC

Proofpoint and IBM X-Force researchers revealed today their part in the operation.

They identified a vulnerability in the StealC C2 panel, which was exploited to help with the disruption operation, and they extracted configurations from many StealC samples.

These configurations contained URLs used to connect to and communicate with the C2 panel, campaign and affiliate IDs, unique client/bot IDs, and C2 communication encryption keys, and were used to track StealC operations and affiliate groups.

They also built a StealC bot emulator, which allowed them to simulate the network activity that occurs in a normal StealC infection, and retrieve and analyze the additional malicious payloads that criminals delivered via this infostealer-cum-dropper.

“In some cases, the StealC client was delivered only one payload, such as another stealer or a remote access trojan (RAT). In many cases, however, the StealC client received another loader malware, which subsequently downloaded the final payload,” the researchers shared.

In one case, StealC downloaded XTinyLoader, which then downloaded a LockBit Black ransomware payload.

Microsoft’s threat analysts also detailed the two Malware-as-a-service operations and shared indicators of compromise pointing to Amadey and StealC infections.

Compromised credentials

According to Europol, nearly 27 million stolen login credentials have been tracked down as part of this operation.

Following the SocGholish infrastructure disruption, compromised credentials have been added to the Have I Been Pwned database, allowing users check whether theirs are among those.

It’s currently unclear whether the same will happen with the latest batch.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!