A major international law enforcement effort has disrupted the infrastructure supporting three prominent malware families used in ransomware attacks and data theft. Coordinated by Europol and Eurojust, Operation Endgame involved agencies from Australia, Belgium, Canada, Denmark, France, Germany, the Netherlands, the United Kingdom and the United States, together with private sector partners. The operation focused on SocGholish, Amadey and StealC. SocGholish acts as a dropper delivered via fake
operationendgame (2)
The Russian government's relationship with its cybercriminal ecosystem has transitioned from passive tolerance to active state management, marking a strategic shift. This report, covering 2024–2025, details the "Dark Covenant 3.0," characterized by selective enforcement, choreographed arrests, and direct coordination between criminal leaders and Russian intelligence intermediaries.
Insikt Group found that Russia leverages these criminal groups as geopolitical tools, with detentions and releases