This situation has concluded
It was preserved as a record on July 28; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [CRIME]
6 clusters · 28 sources · 10 days · First seen · Last updated
Operation Endgame cripples malware, senior fraud spikes
Overview
The June 15‑19, 2026 Operation Endgame raid, coordinated by U.S., German, European and Canadian authorities, disabled 326 command‑and‑control servers, seized 142 domains and blocked more than 320 malicious servers, including the 106 servers that powered the SocGholish fake‑update chain. Roughly 15 000 compromised WordPress sites were cleaned and over 140 000 infected devices were identified worldwide; about 18 000 of those compromised computers were cleaned in Germany alone. Authorities recovered around 27 million stolen credentials from more than 385 000 compromised systems and froze €41 million (≈$47 million) in illicit cryptocurrency. Private‑sector partners—including Bitdefender, ESET, Bitsight, Proofpoint, IBM X‑Force, Germany’s BSI, Infoblox and Microsoft’s Copilot AI—provided intelligence, sink‑hole support and user‑notification. In the days after the raid, investigators dismantled further distribution infrastructure for SocGholish, StealC and Amadey, taking offline roughly 15 000 compromised websites, over 320 servers and more than 140 domains, including about 40 servers in Germany. The operation’s fallout coincided with a sharp rise in fraud targeting seniors: the U.S. FBI reported a 37 % increase in losses for people over 60, reaching $7.7 billion in 2025, while India’s crime bureau noted a 17 % rise in senior‑targeted offences, with a 35 % surge in Telangana. German pension authorities issued warnings about telephone scams. Security researchers also flagged a new phishing‑as‑a‑service platform, Kali365, which hijacks Microsoft 365 accounts by stealing OAuth tokens via the device‑code flow, bypassing MFA. Microsoft responded with updated guidance recommending OAuth 2.1 with PKCE, mandatory schema checks and egress limits. In late June, the German Federal Criminal Police announced a dedicated national anti‑phishing unit to strengthen victim support, threat‑intelligence sharing and cross‑border coordination with Europol and neighboring states.
Timeline
-
3 months ago
[CRIME] 6 sourcesGerman Federal Police Launch New Phishing Unit Amid International Cybercrime CrackdownsGerman police set up a new anti‑phishing unit as BKA and Europol dismantle SocGholish infrastructure; FBI warns of Kali365 token‑theft attacks; senior fraud rises sharply in the US, India and Germany.
-
3 months ago
[TECHNOLOGY] 2 sourcesInfoblox Backs Operation Endgame Takedown of SocGholish Malware InfrastructureInfoblox backs Operation Endgame, which disrupted SocGholish malware by taking down over 100 servers and 15,000 compromised sites, affecting more than half of its customers.
-
3 months ago
[CRIME] 13 sourcesOperation Endgame busts global Amadey, StealC, SocGholish malwareOperation Endgame, a June 2026 international takedown, disabled 326 servers, 142 domains and ~15 000 malicious sites used by Amadey, StealC and SocGholish malware, recovered 27 million stolen credentials and冻结€
-
3 months ago
[CRIME] 8 sourcesOperation Endgame cripples Amadey, StealC and SocGholish malware networksOperation Endgame, a multinational effort, shut down 326 servers, seized 142 domains and froze $47 million in crypto, disrupting Amadey, StealC and SocGholish malware and recovering 27 million stolen passwords.
-
3 months ago
[TECHNOLOGY] 2 sourcesOperation Endgame dismantles SocGholish botnet, seizes 106 servers, cleans 15,000 WordPress sitesOperation Endgame led international authorities to seize 106 servers and clean nearly 15,000 WordPress sites infected by the SocGholish malware, linked to the Russian Evil Corp group.
-
3 months ago
[CRIME] 2 sourcesRussian Evil Corp linked to global fake update scam in multinational police operationCanada, the Netherlands, the US and Germany dismantled a fake‑update scam tied to Russia’s Evil Corp, shutting down 106 servers, cleaning 15,000 WordPress sites and warning users about SocGholish malware.
Sources
archynewsy.com · b2b-cyber-security.de · borncity.com · brf.be · channelpartner.de · cjoy.com · computerworld.dk · cryptobriefing.com · cybersecurity-news.de · esecurityplanet.com · futurezone.de · it-boltwise.de · it-daily.net · langenhagener-news.de · linux-magazin.de · littleonesdaycare.ca · m.olhardigital.uol.com.br · mid-east.info · nationalcybersecurity.com · ncfacanada.org · newsallianz.de · newstalk1290.com · pankower-allgemeine-zeitung.de · seucreditodigital.com.br · technadu.com · wochenblitz.com · wor.com · zdnet.fr