Operation Endgame Hits Amadey and StealC, Pulls 27M Credentials From Loader Infrastructure
Europol-led takedown dismantled command servers behind two prolific malware-as-a-service families, with Bitdefender, Bitsight, ESET and Microsoft providing technical support.

Key points
- Europol's Operation Endgame coordinated the takedown of infrastructure powering Amadey and StealC.
- Roughly 27 million stolen credentials were recovered from seized servers.
- Bitdefender, Bitsight, ESET and Microsoft provided technical support to law enforcement.
- Loader operators historically rebuild within weeks; the 27 million burned credentials are the durable harm.
- Europol has not published a full domain list or arrest figures; the operation is described as ongoing.
What got taken down?
Law enforcement knocked over the backend infrastructure behind Amadey and StealC, two staples of the commodity loader and infostealer market. The action ran under Europol's Operation Endgame banner, with technical input from Bitdefender, Bitsight, ESET and Microsoft. Europol described the goal as disrupting the "assembly lines" cybercriminals use to stage ransomware, financial fraud and attacks on critical infrastructure.
For defenders who don't track commodity malware daily: Amadey is a loader-and-botnet platform first spotted around 2018, typically spread through cracked-software lures or exploit kits. Once installed, it profiles the host and pulls additional payloads on demand. StealC is a younger infostealer, active since early 2023, sold on Russian-language forums and modeled on earlier families like Vidar. It targets browser credentials and session cookies, the raw material that feeds initial-access brokers. Both tools share much of the same customer base; affiliates who buy StealC logs often deploy Amadey to maintain persistence.
On 19 June we covered Operation Endgame's disruption of SocGholish loader infrastructure, and five days later we reported on hundreds of C2 servers going dark in an earlier Amadey and StealC action. This latest round confirms Endgame is working methodically through the commodity tooling tier.
Should you worry about the credentials?
Roughly 27 million stolen credentials were recovered. That number is the headline, but it's also the most actionable part of the story. Those passwords are burned. Any account still using them is exposed whether or not Amadey comes back online.
Check your identity provider's leaked-credential feeds for matches once the dataset is ingested. Hunt for known Amadey and StealC indicators in EDR telemetry going back 90 days; both families leave consistent registry and scheduled-task artifacts. Force password rotation on any account where session cookies may have been exfiltrated. Resetting the password alone doesn't kill an active stolen session. And review your initial-access detections: if a StealC log was sold before the takedown, the buyer still has it.
Will this stick?
Probably not permanently. Loader operators historically rebuild within weeks, often on bulletproof hosting in jurisdictions outside the takedown coalition. Expect indicator drops from the participating vendors soon; Microsoft's DCU and ESET's research team typically publish post-action writeups with hashes and C2 lists worth ingesting.
The loader market abhors a vacuum. Watch affiliate chatter for whichever family inherits the displaced customer base.



