What Happened
Between June 15 and 19, 2026, law enforcement agencies from Belgium, Canada, Denmark, France, Germany, the Netherlands, the United Kingdom, and the United States, coordinated by Europol and Eurojust, executed a two-week operation against the infrastructure behind three linked malware families: Amadey, StealC, and SocGholish. The operation seized 326 servers and 142 domains, disrupted an estimated 200 malicious command-and-control nodes, and recovered 27 million stolen login credentials, according to Europol. Cryptocurrency assets of criminal origin currently valued at more than 47 million USD were identified and restricted. Private-sector partners Bitdefender, Bitsight, ESET, and Microsoft provided technical support.
Why It Matters
Amadey, StealC, and SocGholish represent the opening layer of the cybercrime supply chain that ransomware groups, fraud operators, and data-theft crews rely on for initial access and credential acquisition. Amadey is a modular loader, sold as a service, that stages secondary malware payloads across compromised systems. StealC is a subscription infostealer that harvests credentials, cookies, and browser session data. SocGholish is a drive-by access framework that uses fake browser update lures for initial compromise. Europol described the operation’s strategic goal as dismantling the “assembly lines” that enable downstream ransomware and financial fraud campaigns.
Analyst Note
Targeting the enablement layer rather than named ransomware groups allows a single coordinated action to impose friction across many downstream actors simultaneously, since multiple criminal groups typically share the same loader and stealer infrastructure. However, malware-as-a-service operations have demonstrated resilience: infrastructure typically rebuilds within weeks using redundant hosting. Security teams should monitor for renewed Amadey and StealC distribution activity over the coming weeks, particularly via fake software update lures and cracked-installer distribution channels.
For context on how credential theft drives downstream enterprise risk, see CyberTech’s earlier coverage of the LastPass customer data exposure in the Klue supply chain attack.
Source: Europol