started · updated
Operation Endgame busts global Amadey, StealC, SocGholish malware
Operation Endgame was a coordinated international law‑enforcement and private‑sector effort that ran from 15 to 19 June 2026. Agencies from Germany, the Netherlands, Denmark, the United Kingdom, the United States and Canada worked with Europol, Eurojust, Microsoft and security firms such as Bitdefender, ESET and Proofpoint.
The operation disabled 326 servers, seized more than 140 domains and neutralised roughly 15 000 malicious web sites, including 40 servers located in Germany. It targeted three malware families used as cyber‑crime‑as‑a‑service tools: the dropper SocGholish, the loader Amadey and the infostealer StealC.
Authorities recovered about 27 million stolen login credentials affecting over 385 000 victims and froze roughly €41 million (about $47 million) in cryptocurrency linked to the campaigns. For the first time the U.S. RICO Act was applied to a cybercrime case, and Microsoft’s AI‑driven Copilot was used to map shared infrastructure between the malware families.
Carsten Meywirth, head of the BKA cybercrime unit, said the takedown “undermines the first‑infection stage of a large‑scale global cyber‑crime supply chain and protects countless potential victims.”