Europol Operation Dismantles Malware Networks

31194827881?profile=RESIZE_400xA major international law enforcement effort has disrupted the infrastructure supporting three prominent malware families used in ransomware attacks and data theft. Coordinated by Europol and Eurojust, Operation Endgame involved agencies from Australia, Belgium, Canada, Denmark, France, Germany, the Netherlands, the United Kingdom and the United States, together with private sector partners.  The operation focused on SocGholish, Amadey and StealC.  SocGholish acts as a dropper delivered via fake browser updates on compromised WordPress sites and links to the Russian cybercriminal group Evil Corp.[1]

Amadey spreads via phishing and includes stealer functions to harvest sensitive data. StealC serves as both a stealer and dropper, extracting passwords and digital identities for sale or further criminal use.  These tools formed part of Cybercrime-as-a-Service offerings that enable initial access for ransomware deployment, financial fraud, and attacks on critical infrastructure.  Amadey and StealC alone infected more than 140,000 computers worldwide in the first two weeks of May 2026.

Law enforcement and private partners acted against 326 servers and 142 domains.  They recovered approximately 27 million stolen login credentials and restricted criminal cryptocurrency assets valued at more than €41 million.  For SocGholish, authorities disabled the botnet, remediated 14,971 infected websites, and notified victims through multiple platforms. The operation is described as the largest international effort to tackle ransomware enablers worldwide.  It increased friction for criminals by disrupting the assembly lines used to launch and sustain attacks.

Private-sector organizations participating in the operation included Microsoft, the Shadowserver Foundation, Proofpoint, IBM X-Force, and others that provided technical support, domain management, and victim notification services.  In an expert comment, Dray Agha, senior manager of security operations at Huntress, welcomed the results.  “This coordinated takedown of infrastructure behind StealC, Amadey, and SocGholish is a massive blow to the ransomware supply chain, demonstrating that aggressive, borderless collaboration can successfully dismantle the foundational entry points that cybercriminals rely on to breach organizations.”

He added that the recovery of 27 million credentials highlights the industrial scale of the modern cybercrime economy.  “This serves as a reminder for businesses to strictly enforce Multi-Factor Authentication (MFA) and continuous identity monitoring to render stolen passwords useless.”  Agha noted the prevalence of credential-based attacks: “At Huntress, 70% of the advanced intrusions we observe originate with threat actors using stolen credentials to sign in to the VPN.  It’s malware like these that facilitated that credential theft.  MFA neutralizes this threat.”  The disruption shows the value of sustained international cooperation against cybercrime infrastructure.  Organizations are advised to enable multi-factor authentication, keep software updated, remove unknown accounts, and remain alert to suspicious updates or pop-ups.  The operation demonstrates that combined public and private efforts can degrade the tools criminals rely upon for large-scale breaches.

 

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/europol-operation-dismantles-malware-networks-9492.html

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!