Operation Endgame Hits Amadey and StealC, Pulls 27M Credentials From Loader Infrastructure
Europol-led takedown dismantled command servers behind two of the most prolific malware-as-a-service loaders, with Microsoft, ESET, Bitdefender, and Bitsight providing technical support.

Law enforcement has knocked over the backend infrastructure behind Amadey and StealC, two staples of the commodity loader and infostealer market. The action was coordinated under Europol's ongoing Operation Endgame banner, with technical input from Microsoft, ESET, Bitdefender, and Bitsight.
Roughly 27 million stolen credentials were recovered from the seized infrastructure.
That number is the headline, but the operational story is the disruption itself. Investigators went after what Europol described as the "assembly lines" cybercriminals use to stage follow-on attacks — the dropper layer that precedes ransomware deployment, banking fraud, and intrusions into critical infrastructure operators. Take down the loader, and the downstream affiliate economy stalls.
A quick refresher for defenders who don't track the commodity malware scene daily.
Amadey is a loader-and-botnet platform first spotted around 2018, typically distributed via SmokeLoader, exploit kits, or cracked-software lures. Once resident, it profiles the host and pulls additional payloads on demand. StealC is a younger infostealer (active since early 2023) modeled on Vidar and Raccoon, sold as a subscription on Russian-language forums. It targets browser credentials, crypto wallets, and session cookies — the raw material that feeds initial-access brokers.
Both tools share the same customer base. Affiliates who buy StealC logs often deploy Amadey to maintain persistence and stage the next stage.
The takedown follows the May 2025 Operation Endgame round that disrupted DanaBot, Bumblebee, and Lumma Stealer infrastructure. Treat this as the same playbook, applied to the next tier of tooling.
Defenders should not assume the disruption is permanent. Loader operators historically rebuild within weeks, often on bulletproof hosting in jurisdictions outside the takedown coalition. The 27 million credentials, however, are a one-way data point — those passwords are burned, and any account still using them is exposed regardless of whether Amadey comes back online.
Practical steps worth taking this week:
- Check Have I Been Pwned and your identity provider's leaked-credential feeds for matches against the freshly recovered dataset once it's ingested.
- Hunt for known Amadey and StealC indicators in EDR telemetry going back 90 days. Both families leave consistent registry and scheduled-task artifacts.
- Force password rotation on any account where session cookies may have been exfiltrated. Resetting the password alone doesn't kill an active stolen session.
- Review your initial-access detections. If a StealC log was sold before the takedown, the buyer still has it.
Europol has not yet published the full list of seized domains or arrest figures (the operation is described as ongoing). Expect indicator drops from the participating vendors in the coming days; Microsoft's DCU and ESET's research team typically publish post-action writeups with hashes and C2 lists worth ingesting.
The loader market abhors a vacuum. Watch for affiliate chatter pointing at whichever family inherits the displaced customer base.



