// 2 ZERO-DAY · 2 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate on underground markets, powering groups like Coinbase Cartel to breach cloud, FTP, and file-transfer services.

On June 24, 2026, Microsoft's Digital Crimes Unit, in coordination with Europol, disabled more than 200 domains and IP addresses serving as command-and-control infrastructure for the StealC and Amadey malware families. The operation disrupts an active infrastructure, but it does not solve the structural problem: credential logs stolen before that date still circulate on underground markets and have become the primary fuel for enterprise data breaches targeting cloud, FTP, and file-transfer services.

The danger lies in latency. A credential stolen in 2022 from an employee's personal device can be purchased in 2026, still valid and functional, to compromise a corporate environment. Traditional endpoint defenses miss the risk: access occurs with valid credentials, often from unmanaged devices.

Key Takeaways
  • Microsoft DCU and Europol disabled over 200 StealC and Amadey C2 domains and IPs on June 24, 2026, after the two malware families infected more than 140,000 computers globally in the first two weeks of May 2026.
  • The extortion-only group Coinbase Cartel, which emerged in September 2025, has claimed over 100 victims using exclusively stale infostealer credentials, 80% of which had documented prior infections in Hudson Rock's Cavalier database.
  • An 8.3-terabyte Elasticsearch database containing 24 billion infostealer log records, discovered by Cybernews on June 12, 2026, exposed plaintext credentials from 36 distinct sources, including Telegram channels.
  • Infostealer logs are monetized within hours: from $2 on Russian markets to over $100 for premium logs, with a 48- to 72-hour window between theft and potential enterprise intrusion.

StealC and Amadey: A Modular Malware-as-a-Service Assembly

StealC is an infostealer sold as malware-as-a-service that harvests data from browsers, cryptocurrency wallets, messaging apps, email clients, and gaming platforms. Amadey is a loader MaaS that delivers StealC and other payloads; the two are frequently chained together. According to Microsoft, "Infostealer operators favor delivery techniques that scale and rely on ordinary user behavior rather than software vulnerabilities." No zero-days are required: fraudulent installers, bundling with cracked software, or large-scale phishing campaigns suffice.

In the first two weeks of May 2026, Amadey and StealC were linked to more than 140,000 infected computers worldwide. The figure excludes prior infections and undetected ones: it is a partial snapshot of an ecosystem that has operated for years. The June disruption struck the command-and-control infrastructure, not the secondary market for already-exfiltrated logs.

The Log Market: From $2 to Over $100, With Commodity Liquidity

Infostealer logs have become a liquid commodity. Microsoft documents prices ranging from $2 per log on Russian markets to $10–50 for standard logs and over $100 for premium logs. Monetization is rapid: credentials appear on Telegram channels or dark-web markets within hours of theft. The critical data point is the speed of transition to enterprise use. Microsoft estimates a 48- to 72-hour window between credential theft and potential corporate intrusion, although some logs lie dormant for months or years before organized groups purchase them.

This economy has lowered the barrier to entry. Attackers without advanced technical skills can buy valid access and proceed to extortion or ransomware. No exploit development is needed: only modest starting capital and connections to the right markets.

"Coinbase Cartel exclusively uses old Infostealer credentials to compromise cloud environments, FTP servers, and file transfer services" — Hudson Rock, infostealers.com

Coinbase Cartel: The Case Study of 100+ Breaches Without an Exploit

The extortion-only group Coinbase Cartel, which emerged in September 2025, is operational proof of the infostealer-to-breach chain. Hudson Rock documented over 100 companies breached by the group, with a recurring pattern: 80% of victims had prior infostealer infections indexed in Hudson Rock's proprietary Cavalier database. The credentials used are often years old, collected long before the actual attack. This confirms that initial compromise and corporate intrusion are separate events in time, linked only by the log market.

The group employs no sophisticated techniques or zero-day vulnerabilities. It selects targets based on the availability of valid credentials on underground markets and proceeds with direct access. The absence of exploits renders the activity invisible to traditional endpoint defenses, which are designed to detect anomalous behavior or malicious payloads, not authenticated sessions with legitimate credentials.

The 24-Billion-Record Database: The Scale of the Problem

On June 12, 2026, Cybernews discovered an exposed 8.3-terabyte Elasticsearch database containing 24 billion records, predominantly infostealer logs with plaintext credentials: usernames, email addresses, cleartext passwords, and login URLs. The records originated from 36 distinct sources, including 1.7 billion from hacking-oriented Telegram channels and 22.6 billion from 'collections' grouped by access service.

The database belonged to a threat-intelligence and breach-monitoring platform, not criminal operators. It was exposed due to a misconfiguration during a temporary migration. Cybernews cannot quantify duplicates or the number of unique individuals affected. The data nevertheless illustrates the concentration of compromised credentials in a single repository and the risk stemming from accidental exposures of security infrastructure itself.

The Cybernews research team emphasized that "the credential data leak is dangerous simply because of its enormous size. Since the data leaked online, billions of affected accounts are at serious risk of takeovers, especially if they are not protected with multi-factor authentication." The lack of MFA emerges as an amplifying risk factor, although the dossier does not document the exact percentage of accounts in the database that lacked it.

What to Do Now

  • Audit cloud access and file-transfer services with historical logs: compromised credentials can be years old and not tied to recent security events.
  • Enforce MFA on all corporate accounts and cloud services accessible via credentials, including those considered secondary or legacy.
  • Map unmanaged or BYOD devices that access corporate resources: infostealer infections typically occur on personal endpoints, not on controlled corporate assets.
  • Monitor threat-intelligence markets for the presence of corporate credentials in infostealer logs, integrating this visibility into incident-response programs.

Why the June Disruption Does Not Close the Case

The Microsoft-Europol operation on June 24, 2026, is tactically relevant: it disrupts an active C2 infrastructure and temporarily slows StealC and Amadey operators. Strategically, however, the problem remains open. Already-stolen logs do not vanish when command-and-control servers are taken down. They continue to circulate, to be resold, and to be used by groups like Coinbase Cartel to compromise cloud environments with valid credentials.

The threat model has shifted its center of gravity from technical exploit to the access market. Enterprises must adapt defenses to this shift: risk no longer resides solely in software vulnerabilities, but in the indefinite persistence of stolen credentials and their commercialization at marginal cost. Password rotation, MFA, and visibility into unmanaged devices become not optional controls, but structural ones.

Frequently Asked Questions

Are StealC and Amadey the only active infostealers?

No. Parallel ecosystems exist with malware such as Lumma, RedLine, Vidar, and Raccoon. The June disruption targeted a specific pair of threats, not the entire market.

Was the 24-billion-record database run by criminals?

No. According to Cybernews, it belonged to a legitimate threat-intelligence and breach-monitoring platform and was exposed due to a misconfiguration during a migration.

Why are years-old credentials still working?

The dossier documents that many credentials are never rotated: employees reuse passwords, companies fail to revoke access to abandoned cloud services, and MFA is not widely implemented. The log market exploits this inertia.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. microsoft.com
  2. infostealers.com
  3. cybernews.com
  4. techdigest.tv
  5. blogs.microsoft.com