
Operation Endgame Phase 2: StealC & Amadey infrastructure dismantled by ESET, Microsoft, and partners
We Live Security
•
Wednesday, June 24, 2026
•
International
A major coordinated cybercrime disruption operation concluded on June 24, 2026, targeting the backend infrastructure of StealC and Amadey — two prolific tools in the cybercriminal ecosystem. StealC is an infostealer capable of silently harvesting credentials, passwords, and sensitive user data, while Amadey functions as a malware loader used to distribute additional payloads across compromised systems. The joint action involved ESET Research providing threat intelligence and Microsoft's Digital Crimes Unit executing domain suspensions, takedowns, and blocking actions against the core infrastructure supporting both operations. This disruption represents the latest phase of Operation Endgame, a sustained international effort to dismantle top-tier cybercriminal services. Previous phases in 2025 successfully targeted Lumma Stealer and Danabot. The recurring cadence of these operations signals an ongoing, coordinated strategy by law enforcement and private sector partners to systematically degrade the infrastructure that enables large-scale credential theft and malware distribution globally. ## Latest Update As of June 24, 2026, Microsoft's DCU has confirmed the facilitated takedown and blocking of domains forming the backbone of StealC and Amadey infrastructure. ESET simultaneously published technical analysis detailing both malware families and their roles in the broader cybercrime-as-a-service ecosystem. This marks the first public confirmation of this specific phase of Operation Endgame targeting these two platforms. ## Timeline - **2025 (prior phases):** ESET Research participates in Operation Endgame actions disrupting Lumma Stealer and Danabot infrastructure. - **2026-06-24T12:30:00Z (Microsoft):** Microsoft's Digital Crimes Unit announces facilitated takedown, suspension, and blocking of domains supporting StealC and Amadey; publishes technical breakdown of both infostealer families. - **2026-06-24T12:35:00Z (ESET/We Live Security):** ESET Research publicly confirms participation in the latest Operation Endgame phase, detailing its intelligence contributions to the disruption of Amadey and StealC. ## What to Watch - **Infrastructure reconstitution:** Threat actors behind StealC and Amadey may attempt to rapidly rebuild on new domains or bulletproof hosting — monitor for reemergence of C2 activity associated with these malware families. - **Credential exposure fallout:** Data already harvested by StealC and Amadey prior to the takedown may still be circulating on criminal markets; individuals and organizations should monitor for credential leaks and consider proactive password resets on sensitive accounts. - **Operation Endgame Phase 3:** Given the pattern of sequential takedowns, watch for announcements targeting other major infostealer or loader platforms (e.g., RedLine, RisePro, or similar services) as the next likely focus of coordinated action.