International law enforcement agencies and private sector partners successfully dismantled the criminal infrastructure powering the Amadey and StealC malware families, disrupting a major global cybercrime-as-a-service network.
Key Points
- Authorities seized 326 servers and 142 domains used to distribute malware and manage command-and-control operations.
- The operation recovered 27 million stolen login credentials and restricted over $47 million in illicit cryptocurrency assets.
- Private sector partners including Microsoft, Bitdefender, ESET, and Bitsight collaborated with agencies from the U.S., Europe, and Canada.
- Amadey and StealC functioned as malware-as-a-service platforms, enabling affiliates to deploy ransomware and steal sensitive data from compromised hosts.
- Microsoft identified over 140,000 infected computers globally during the first two weeks of May 2026, leading to targeted remediation efforts.