< Back to all clusters
[CRIME] · United States, Germany, Netherlands, Denmark, United Kingdom · 8 sources

started · updated

Operation Endgame cripples Amadey, StealC and SocGholish malware networks

International law‑enforcement agencies and private cybersecurity firms coordinated Operation Endgame from 15‑19 June 2026 to dismantle the infrastructure of three high‑profile malware families – Amadey, StealC and SocGholish. Participants included the US Department of Justice, the German Federal Criminal Police Office (BKA), Europol, Eurojust, and police forces from the Netherlands, Denmark, the United Kingdom, Canada and France, supported by Microsoft, ESET, Proofpoint, IBM X‑Force and other industry partners.

The operation disabled 326 command‑and‑control servers, seized 142 domains and blocked more than 320 malicious servers, including 106 servers used by the SocGholish “FakeUpdates” chain. Around 15 000 compromised websites were cleaned, and over 140 000 infected devices were identified. Authorities recovered roughly 27 million stolen credentials from more than 385 000 compromised systems and froze €41 million (about $47 million) in illicit cryptocurrency assets.

Microsoft leveraged its Copilot AI tool to analyse malware binaries and help build a RICO‑based civil lawsuit in the United States, treating the two malware families as a single organized‑crime enterprise. The coordinated takedown is expected to hinder future ransomware and credential‑stealing campaigns that relied on these tools.