Tidavo
Wednesday 7 October 2026

International Coalition Knocks Out Network Infrastructure Powering Two Prominent Cybercrime Services

Law enforcement agencies and technology firms have disabled dozens of domains and nearly 200 control servers running the Amadey and Stealc malicious networks.

7 Oct 2026

A global operation involving technology corporations, independent security specialists, and law enforcement agencies has disrupted the digital infrastructure underpinning two widespread malicious programs. The targeted threats, known as Amadey and Stealc, have long operated as commercial crime services used by numerous independent actors to hijack consumer computers and siphon personal data.

The sweep, carried out under the banner of Operation Endgame, knocked out approximately 50 internet domains and nearly 200 active internet protocol addresses that served as command centers. The multinational coordination pulled together expertise from Microsoft's Digital Crimes Unit, BitSight, Lumen, Mitsui Bussan Secure Directions, and security firm ESET, alongside public authorities seeking to dismantle criminal distribution networks.

The two malware strains play different roles in modern digital intrusions. Amadey functions as a loader, acting as an initial foothold on an infected computer. Its primary assignment is to deploy additional payloads selected by the attacker, though it also contains built-in capabilities to log keystrokes, monitor clipboard activity, steal stored credentials, and open remote desktop connections.

Stealc specializes strictly in data extraction. Designed to silently harvest value from an infected device, it searches for browser-stored login details, authentication cookies, cryptocurrency wallet records, browser extensions, and specific personal files matching patterns designated by the attacker.

Both tools thrive on a subscription-style business model advertised on subterranean digital forums. Rather than launching individual attacks, the creators sell software licenses to criminal buyers. Amadey, which has been marketed by an individual using the alias InCrease since October 2018, charges a base license fee of $600 in cryptocurrency, adding a $50 surcharge whenever a customer requests a fresh build of the program. Stealc takes a slightly different commercial stance, granting buyers unlimited program builds within their subscription window.

Unlike centralized cybercrime services that host everything for their customers, Amadey and Stealc require affiliates to establish and administer their own separate server infrastructure. This decentralized setup gives buyers total autonomy over their operational records and stolen files, while historically making comprehensive enforcement actions difficult because there was no single central server to unplug.

To counter this decentralized architecture, security analysts spent several years reverse-engineering samples to group disparate servers into identifiable clusters. By extracting cryptographic keys, build tags, and network handshake sequences embedded within the software files, investigators reconstructed the broader web of operations and linked seemingly isolated servers to specific customer campaigns.

Most victims encountered the malicious files while attempting to download pirated software, cracked utilities, or through deceptive web prompts mimicking routine program updates. Once installed, the software establishes communication with affiliate-run control points through encoded web requests, transmitting machine specifications and retrieving execution orders.

One notable technical detail found in Amadey is a region-based safeguard: the software actively checks the victim's keyboard settings and cancels all network traffic if it detects a configuration typical of post-Soviet nations. This mechanism is frequently used by Eastern European cybercrime developers to shield domestic users, thereby dampening local law enforcement scrutiny while turning overseas computer users into their primary targets.

WeLiveSecurity