Microsoft AI operation dismantles global malware networks
Microsoft’s Digital Crimes Unit used its Copilot artificial‑intelligence assistant to analyse the code of two widely used malware platforms, Amadey and StealC, and uncover the infrastructure that linked them. Working with Europol and law‑enforcement agencies in Australia, Belgium, Canada, Denmark, France, Germany, the Netherlands, the United Kingdom and the United States, the joint effort neutralised 326 servers and 142 domains, recovered more than 27 million stolen credentials, blocked crypto assets worth over €41 million and cleaned more than 14 000 compromised websites. The operation also targeted a third tool, SocGholish, linked to the Russian‑based Evil Corp group. Described as part of “Operation Endgame”, the takedown is the largest coordinated disruption of ransomware‑as‑a‑service infrastructure to date, showing how AI can accelerate the detection and dismantling of complex cyber‑crime networks.