Global Law Enforcement Operation Dismantles Amadey and StealC Malware Networks, Recovers 27 Million Stolen Credentials
A coordinated international law enforcement operation has successfully disrupted the criminal infrastructure behind two prolific cybercrime tools: the Amadey malware loader and the StealC information stealer. Europol announced the action was carried out in partnership with private sector companies including Bitdefender, Bitsight, ESET, and Microsoft. Investigators managed to seize servers and recover approximately 27 million stolen credentials that had been harvested from victims worldwide.
Amadey has functioned for several years as a “loader” — malware whose primary purpose is to establish a foothold on compromised systems and then pull down additional payloads, including ransomware, banking trojans, and stealers. StealC, meanwhile, is an infostealer sold as a service on criminal forums, designed to harvest credentials, cookies, and financial data from infected machines. Together, the two tools formed a key part of the pipeline that cybercriminals use to move from initial infection to large-scale ransomware deployment or financial fraud. Europol characterized the disruption as targeting the “assembly lines” of modern cybercrime operations.
The recovery of 27 million credentials is particularly notable, as these records would otherwise have been available for sale on criminal markets and used in account-takeover attacks against individuals and organizations globally. Authorities have not yet specified how many suspects were arrested as part of the operation, but the infrastructure takedown is expected to significantly degrade the operational capacity of affiliates who relied on these tools.