# Operation Endgame cripples malware, senior fraud spikes

> Live situation record from CLSTR: https://clstr.news/situations/operation-endgame-cybercrime-takedown
> Updated: 2026-06-28T01:44:14.000Z. Sources: 28. Developments: 6.

The June 15‑19, 2026 Operation Endgame raid, coordinated by U.S., German, European and Canadian authorities, disabled 326 command‑and‑control servers, seized 142 domains and blocked more than 320 malicious servers, including the 106 servers that powered the SocGholish fake‑update chain. Roughly 15 000 compromised WordPress sites were cleaned and over 140 000 infected devices were identified worldwide; about 18 000 of those compromised computers were cleaned in Germany alone. Authorities recovered around 27 million stolen credentials from more than 385 000 compromised systems and froze €41 million (≈$47 million) in illicit cryptocurrency. Private‑sector partners—including Bitdefender, ESET, Bitsight, Proofpoint, IBM X‑Force, Germany’s BSI, Infoblox and Microsoft’s Copilot AI—provided intelligence, sink‑hole support and user‑notification. In the days after the raid, investigators dismantled further distribution infrastructure for SocGholish, StealC and Amadey, taking offline roughly 15 000 compromised websites, over 320 servers and more than 140 domains, including about 40 servers in Germany. The operation’s fallout coincided with a sharp rise in fraud targeting seniors: the U.S. FBI reported a 37 % increase in losses for people over 60, reaching $7.7 billion in 2025, while India’s crime bureau noted a 17 % rise in senior‑targeted offences, with a 35 % surge in Telangana. German pension authorities issued warnings about telephone scams. Security researchers also flagged a new phishing‑as‑a‑service platform, Kali365, which hijacks Microsoft 365 accounts by stealing OAuth tokens via the device‑code flow, bypassing MFA. Microsoft responded with updated guidance recommending OAuth 2.1 with PKCE, mandatory schema checks and egress limits. In late June, the German Federal Criminal Police announced a dedicated national anti‑phishing unit to strengthen victim support, threat‑intelligence sharing and cross‑border coordination with Europol and neighboring states.

## Timeline

### 2026-06-28: German Federal Police Launch New Phishing Unit Amid International Cybercrime Crackdowns

German police set up a new anti‑phishing unit as BKA and Europol dismantle SocGholish infrastructure; FBI warns of Kali365 token‑theft attacks; senior fraud rises sharply in the US, India and Germany.

6 sources. https://clstr.news/cluster/bka-and-europol-dismantle-socgholish-stealc-and-amadey-malware-infrastructure

### 2026-06-25: Infoblox Backs Operation Endgame Takedown of SocGholish Malware Infrastructure

Infoblox backs Operation Endgame, which disrupted SocGholish malware by taking down over 100 servers and 15,000 compromised sites, affecting more than half of its customers.

2 sources. https://clstr.news/cluster/infoblox-backs-operation-endgame-takedown-of-socgholish-malware-infrastructure

### 2026-06-24: Operation Endgame busts global Amadey, StealC, SocGholish malware

Operation Endgame, a June 2026 international takedown, disabled 326 servers, 142 domains and ~15 000 malicious sites used by Amadey, StealC and SocGholish malware, recovered 27 million stolen credentials and冻结€

13 sources. https://clstr.news/cluster/microsoft-and-europol-dismantle-global-cybercrime-service-network

### 2026-06-23: Operation Endgame cripples Amadey, StealC and SocGholish malware networks

Operation Endgame, a multinational effort, shut down 326 servers, seized 142 domains and froze $47 million in crypto, disrupting Amadey, StealC and SocGholish malware and recovering 27 million stolen passwords.

8 sources. https://clstr.news/cluster/operation-endgame-dismantles-amadey-stealc-and-socgholish-malware-networks

### 2026-06-20: Operation Endgame dismantles SocGholish botnet, seizes 106 servers, cleans 15,000 WordPress sites

Operation Endgame led international authorities to seize 106 servers and clean nearly 15,000 WordPress sites infected by the SocGholish malware, linked to the Russian Evil Corp group.

2 sources. https://clstr.news/cluster/operation-endgame-dismantles-socgholish-botnet-seizes-106-servers-cleans-15000-wordpress-sites

### 2026-06-18: Russian Evil Corp linked to global fake update scam in multinational police operation

Canada, the Netherlands, the US and Germany dismantled a fake‑update scam tied to Russia’s Evil Corp, shutting down 106 servers, cleaning 15,000 WordPress sites and warning users about SocGholish malware.

2 sources. https://clstr.news/cluster/russian-evil-corp-linked-to-global-fake-update-scam-in-multinational-police-operation

---
Cite as: Operation Endgame cripples malware, senior fraud spikes. CLSTR, https://clstr.news/situations/operation-endgame-cybercrime-takedown
