Home Cyber Security News Europol Disrupts SocGholish, Amadey, and StealC Malware Networks in Global Cyber Strike

Europol Disrupts SocGholish, Amadey, and StealC Malware Networks in Global Cyber Strike

0
Europol Disrupts SocGholish, Amadey, and StealC Malware Networks in Global Cyber Strike

Europol, alongside international law enforcement and private-sector partners, has delivered a landmark blow to cybercriminals’ infrastructure, the largest international operation ever undertaken to dismantle ransomware enablers.

This effort, part of Operation Endgame, was announced on June 24, 2026, and coordinated actions over two weeks targeted the criminal ecosystems behind widely used malware families: SocGholish, Amadey, and StealC.

The operation involved law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States, as well as private partners including Microsoft, Proofpoint, IBM X-Force, Bitdefender, Shadowserver Foundation, and Have I Been Pwned (HIBP).

Authorities seized or disabled 326 servers and 142 domains, severely disrupting malware distribution networks. Crypto assets of criminal origin currently valued at over EUR 41 million (≈ USD 47 million) were identified, flagged, and restricted from use.

Europol Disrupts Cybercrime-as-a-Service Networks

As many as 27 million stolen login credentials were recovered during the operation, and 14,971 infected websites, including restaurants, auto repair shops, and everyday services, were remediated as part of the SocGholish-focused actions.

These malware variants operated under a “cybercrime-as-a-service” model, rented out to other criminals as entry points into targeted systems before ransomware was deployed or financial fraud was committed.

SocGholish, which distributes fake browser updates through compromised WordPress websites. Once installed, it granted threat actors unauthorized access for further exploitation, including ransomware deployment.

SocGholish is attributed to Evil Corp, the Russian cybercriminal group previously responsible for the Zeus and Dridex malware families, and associated with large-scale ransomware and money-laundering operations.

StealC, classified as a stealer with dropper functionality, spreads through multiple attack vectors. It was primarily designed to harvest passwords, stored credentials, and digital identities from compromised systems, making them available for data trading and financial fraud.

Amadey, distributed primarily through phishing campaigns, served as a first-stage payload that could introduce additional malware into compromised systems.

It also carried stealer capabilities, enabling it to exfiltrate sensitive data in addition to its loader functions. According to Microsoft intelligence, in just the first two weeks of May 2026, Amadey and StealC combined were linked to over 140,000 infected computers worldwide.

Europol stated that Operation Endgame marks a deliberate change in law enforcement strategy, moving away from targeting individual threats toward dismantling the entire cybercrime “assembly line.”

By simultaneously disrupting loaders, stealers, and their supporting infrastructure, the coalition significantly increased friction for threat actors attempting to launch, spread, or rebuild attacks.

Europol’s European Cybercrime Center (EC3) provided cross-border attribution analysis, cyber intelligence, and crypto tracing expertise to track illicit financial flows throughout the operation.

Victim notifications were distributed via platforms such as HaveIBeenPwned, Spamhaus, Shadowserver, CheckjeHack, NoMoreLeaks, and NL-NCSC, alerting website owners whose credentials had been exposed.

The Joint Cybercrime Action Taskforce (J-CAT) ensured national investigations were aligned under a cohesive operational framework, with real-time information sharing facilitated through Europol’s SIENA platform.

Dutch Police urge all WordPress administrators to immediately change their login credentials, enable multi-factor authentication (MFA), delete any unknown additional user accounts, and keep their platforms fully updated.

Users should also remain vigilant against browser pop-ups and unsolicited update prompts.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here