An international law-enforcement and private-sector operation dismantled the shared infrastructure of the Amadey loader and StealC infostealer between June 15–19, 2026, seizing or disabling 326 servers, 142 domains, and over 200 C2 endpoints, recovering roughly 27 million stolen credentials from 385,000 compromised systems, and freezing more than $47 million in criminal cryptocurrency. For the first time, the Racketeer Influenced and Corrupt Organizations Act (RICO) was used to treat two distinct malware families as a single conspiracy, opening a legal avenue that could reshape the economics of Malware-as-a-Service disruption.

An internationally coordinated action between law enforcement and the private sector dismantled the shared infrastructure of the Amadey loader and StealC infostealer between June 15 and 19, 2026: 326 servers, 142 domains, and over 200 command-and-control endpoints seized or disabled, roughly 27 million stolen credentials recovered from 385,000 compromised systems, and more than $47 million in criminal cryptocurrency frozen. The novelty is not only technical: for the first time, the Racketeer Influenced and Corrupt Organizations Act (RICO) was used to treat two distinct malware families as a single conspiracy, opening a legal line that could redefine the economics of combating Malware-as-a-Service.

Key Takeaways
  • The operation recovered roughly 27 million credentials from 385,000 compromised systems and identified over $47 million in criminal cryptocurrency assets, according to Europol.
  • Microsoft isolated over 18,000 victim computers, but May 2026 data indicates more than 140,000 combined infections in the first two weeks alone: the majority of compromised machines remain unknown to victims.
  • Microsoft's AI analysis revealed that Amadey (active since 2018) and StealC (since 2023) shared C2 infrastructure, enabling a unique RICO Act action against both.
  • ESET mapped 53 Amadey affiliate clusters using an RC4-key and build-identifier clustering methodology; Proofpoint and IBM X-Force exploited a vulnerability in the StealC C2 panel to extract configurations.

How Amadey and StealC Shared the Same "Digital Asphalt"

Amadey and StealC are two technically independent operations. Amadey, present since 2018 in its latest version 5.87, functions as a loader: purchased for $600 plus $50 per recompile, it distributes secondary payloads such as Lumma Stealer, Vidar, RedLine, SmokeLoader, and AsyncRAT through an ecosystem of 53 affiliate clusters identified by ESET. StealC, active from version 2.2.1 since January 2023 with an update in June 2026, is an infostealer with a subscription model: $300 per month or $1,000 for six months.

The discovery that procedurally united them did not come from traditional investigative intuition. Microsoft employed its own AI analysis system — based on Copilot — to uncover infrastructural overlaps between the two ecosystems that were not evident on manual inspection. Steven Masada, Assistant General Counsel of Microsoft's Digital Crimes Unit, explained the conceptual leap: those analyses allowed the legal team to treat both malware families as part of a single conspiracy, rather than pursuing each tool separately as done in the past.

This step enabled invocation of the RICO Act, a law designed to dismantle structured criminal organizations, against a network of complicit "enablers" operating through both malware. It is not a mere legal expedient: RICO allows civil sanctions and asset seizure, with a systemic logic different from the individual pursuit of single operators, known only by the pseudonyms "InCrease" (Amadey) and "plymouth" (StealC).

Disruption Techniques: From RC4 Clustering to C2 Panel Vulnerability

The technical component of the operation articulated across three independent lines that then converged in the legal action. ESET, which has tracked Amadey for three years, applied a clustering methodology based on RC4 keys and build identifiers to isolate individual affiliate botnets: it disabled roughly 50 domains and nearly 200 active IP-based C2 servers. The method distinguishes apparently identical operations based on cryptographic artifacts, not static signatures — an approach particularly effective against malware whose pay-per-rebuild model generates polymorphic samples with every recompile.

Proofpoint and IBM X-Force operated on the other front, identifying a vulnerability in the StealC C2 administration panel that allowed web shell upload and extraction of operational configurations. The collaboration also produced a bot emulator capable of simulating infections and retrieving payloads in real time, enriching the evidentiary framework for the legal action. Microsoft ultimately reported over 200 malicious domains and C2 IP addresses, disabled through court orders and provider notifications.

"When multiple parts of an operation are disrupted together, attacks are harder to launch, scale, and recover from" — Steven Masada, Microsoft Digital Crimes Unit

The Numbers That Don't Add Up: Why 18,000 Known Victims Versus 140,000 Infections

The discrepancy between the 18,000 victim computers identified and isolated by Microsoft and the more than 140,000 combined infections detected in the first two weeks of May 2026 is the most unsettling figure for organizations. It means the majority of compromised machines were not recognized even during active intelligence phases. Amadey and StealC are not noisy payloads: StealC self-terminates if it detects a system locale in Russia, Ukraine, Belarus, Kazakhstan, or Uzbekistan — behavior typical of operators limiting local judicial exposure; Amadey operates as a silent intermediary, often preceding actual credential theft.

The MaaS model with self-hosted administration panels — each affiliate must deploy its own server — adds another layer of difficulty. Even with the central infrastructure disabled, affiliates with independent operational panels can rebuild quickly. The sources do not specify corrective measures that prevent this reconstruction, and no arrests emerge that reduce the operational capacity of the known managers.

What to Do Now

Organizations must verify the presence of Amadey and StealC IoCs in their environments: the prevalence of unidentified infections makes retrospective scanning a priority. The recovery of 27 million credentials signals a systemic risk of password reuse that requires forced reset of corporate credentials and verification of any overlaps with known compromise databases. Detection must prioritize typical loader behaviors — staged payload execution, C2 communications following an initial contact — over signature-based detection, given the polymorphic generation associated with the pay-per-rebuild model. Finally, the mapping of the 53 Amadey affiliate clusters published by ESET provides indicators of sufficient specificity to guide network checks on behavioral rather than merely signature-based grounds.

The RICO Precedent and the Economics of MaaS Disruption

The real stakes of Operation Endgame are not measured only in disabled servers. Applying the RICO Act to a dual-malware case establishes that shared infrastructure — not just malicious code — can be treated as a unified criminal organization. This shifts the legal target from the single tool to the system of "enablers" that makes it scalable: hosting, domain registration, cryptocurrency services, affiliate panels.

The source does not specify whether the civil RICO action will proceed toward criminal charges or remain a civil enforcement tool. It is also not documented whether the same approach will be replicated against similar MaaS ecosystems such as Lumma Stealer or RedLine, technically cited in Amadey's payloads but not included in the action. What the dossier confirms is that AI analysis of infrastructural connections made possible an operation that manual inspection would not have identified: a change in investigation costs that, if replicated, alters the cost-benefit calculations of criminal operators.

For now, the most brutal metric remains that of infections: 140,000 machines versus 18,000 known victims means that active self-defense by organizations remains the only line that works in real time, regardless of the speed of public-private cooperation.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. thehackernews.com
  2. helpnetsecurity.com
  3. bleepingcomputer.com
  4. securityweek.com
  5. cyberscoop.com
  6. welivesecurity.com