AUTO-UPDATED

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

International law enforcement agencies and private sector partners successfully dismantled the criminal infrastructure powering the Amadey and StealC malware families, disrupting a major global cybercrime-as-a-service network.

Key Points

  • Authorities seized 326 servers and 142 domains used to distribute malware and manage command-and-control operations.
  • The operation recovered 27 million stolen login credentials and restricted over $47 million in illicit cryptocurrency assets.
  • Private sector partners including Microsoft, Bitdefender, ESET, and Bitsight collaborated with agencies from the U.S., Europe, and Canada.
  • Amadey and StealC functioned as malware-as-a-service platforms, enabling affiliates to deploy ransomware and steal sensitive data from compromised hosts.
  • Microsoft identified over 140,000 infected computers globally during the first two weeks of May 2026, leading to targeted remediation efforts.

Why it Matters

This operation significantly disrupts the "assembly line" of cybercrime by targeting the initial access loaders that serve as gateways for ransomware and financial fraud. By dismantling these infrastructures, authorities have hindered the ability of threat actors to scale their operations and monetize stolen credentials on a global level.
Internet Published by info@thehackernews.com (The Hacker News)
Read original