Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft and Partners Dismantle Amadey and StealC Malware

Microsoft and Partners Dismantle Amadey and StealC Malware

Posted on June 24, 2026 By CWS

In a significant blow to cybercrime, Microsoft has joined forces with law enforcement and cybersecurity firms to dismantle the shared infrastructure of the Amadey and StealC malware families. This collaborative effort, known as Operation Endgame, utilized advanced technologies, legal strategies, and a vulnerability in a malware control panel to target numerous domains and servers.

Operation Endgame and Its Impact

Operation Endgame has been a long-standing initiative aimed at disrupting cybercriminal activities. In this instance, the operation focused on what authorities and companies referred to as the “cybercrime assembly line,” marking a departure from traditional strategies that typically target specific threats. This innovative approach has led to the targeting of hundreds of domains and servers associated with the Amadey and StealC malware.

Amadey, operational since 2018, acts as a malware-as-a-service loader, facilitating unauthorized access for threat actors to deploy secondary attacks. StealC, introduced in 2023, is an infostealer that extracts credentials, cryptocurrency wallets, cookies, and other sensitive information. The two malware often operate in tandem, enhancing the threat level posed to systems worldwide.

AI and Collaborative Efforts

AI-powered analysis played a crucial role in identifying the shared command-and-control (C&C) infrastructure used by Amadey and StealC. This discovery enabled Microsoft and its partners to effectively execute takedown operations. According to Europol, this operation signifies a strategic shift, focusing on dismantling the entire cyberattack chain rather than isolated threats.

The operation led to the seizure of over 25 million unique credentials from more than 385,000 systems, alongside the identification and securing of 18,000 compromised computers. Additionally, crypto assets worth over $47 million were located and flagged to restrict unauthorized use.

Exploiting Vulnerabilities and Future Implications

A vulnerability in the StealC C&C panel was crucial in the operation, allowing the upload of a web shell to gather data. Although this flaw was instrumental in supporting the takedown, it was also exploited by a StealC affiliate to steal data from other affiliates. This dual use of the vulnerability highlights the complexity of cyber operations.

Key partners in this operation, including Microsoft, Europol, ESET, Bitsight, IBM X-Force, Proofpoint, and Mitsui Bussan Secure Directions, have detailed their actions in various publications. This collaborative effort follows the recent dismantling of the SocGholish botnet, showcasing ongoing global efforts to combat cyber threats.

The successful disruption of the Amadey and StealC infrastructure underscores the importance of collaborative approaches in cybersecurity. As cybercriminal tactics evolve, so too must the strategies employed by those working to protect digital landscapes.

Security Week News Tags:AI, Amadey, Cybercrime, Cybersecurity, Europol, law enforcement, Malware, Microsoft, Operation Endgame, StealC

Post navigation

Previous Post: GhostShell Malware Targets Ukrainian Drones Using mTLS and Telegram
Next Post: Global Operation Targets Major Cybercrime Infrastructure

Related Posts

CISA Alerts on Active Gitea Vulnerability Exploitation CISA Alerts on Active Gitea Vulnerability Exploitation Security Week News
Threat Actor Connected to Play, RansomHub and DragonForce Ransomware Operations Threat Actor Connected to Play, RansomHub and DragonForce Ransomware Operations Security Week News
Chrome 143 Patches High-Severity Vulnerabilities Chrome 143 Patches High-Severity Vulnerabilities Security Week News
3 Million Stolen in Cetus Protocol Hack $223 Million Stolen in Cetus Protocol Hack Security Week News
F5 Hack: Attack Linked to China, BIG-IP Flaws Patched, Governments Issue Alerts  F5 Hack: Attack Linked to China, BIG-IP Flaws Patched, Governments Issue Alerts  Security Week News
Preemptive Security Urged as Cyber Threats Accelerate Preemptive Security Urged as Cyber Threats Accelerate Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cloudflare Secures Containers After Disk Data Exposure
  • Bitget Hot Wallet Breach Exposes $351.6 Million
  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cloudflare Secures Containers After Disk Data Exposure
  • Bitget Hot Wallet Breach Exposes $351.6 Million
  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark