International authorities and private technology companies initiated a coordinated action, known as Operation Endgame, to disrupt cybercrime operations involving the malware tools Amadey and StealC. The operation recovered millions of login credentials and over $47 million in ransom payments and other fraudulent funds.
Microsoft determined that Amadey and StealC relied on some of the same underlying infrastructure. The technology company analyzed these tools using artificial intelligence to identify their shared infrastructure. Microsoft attorneys then invoked RICO statutes to seek a court order disrupting both tools simultaneously, treating them as part of a single conspiracy.
As part of the operation, Microsoft disrupted more than 200 command-and-control servers and severed criminal control of more than 18,000 infected computers. Europol helped coordinate the law enforcement aspects of the operation. Europol said it recovered as many as 27 million stolen login credentials and uncovered $47 million worth of crypto assets of criminal origin.
Europol stated, "During this action, 326 servers and 142 domains were actioned by law enforcement and the private sector partners, severely crippling the malware's distribution network." Microsoft described the action as targeting the cybercrime "assembly line" that drives ransomware, financial fraud, and public service disruptions.
Various private sector partners assisted in Operation Endgame, including ESET, Proofpoint, IBM X-Force, Bitsight, and Mitsui Bussan Secure Directions. Europol said, "By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cybercriminals, making it harder for attacks to succeed, spread, or recover."
Amadey, a malware-as-a-service platform, is used for compromising devices and delivering malicious payloads for ransomware and other scams. It has been active since at least 2018 and has been observed abusing GitHub to collect system information and install customized payloads. StealC is an infostealer-as-a-service platform designed to collect credentials, authentication cookies, cryptocurrency wallets, browser extensions, and files matching customer-defined patterns. Microsoft said, "Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information."
Europol also reported a disruption of SocGholish, a malware loader linked to the Russian cybercrime group Evil Corp, as part of Operation Endgame. SocGholish spreads by tricking website visitors into installing trojanized applications. Europol cleaned infected WordPress sites, urged administrators of infected sites to change credentials and tighten security, and worked to notify parties whose data and credentials were exposed through SocGholish activities. Countries involved in the enforcement action include Canada, Denmark, Germany, the Netherlands, the U.K., and the U.S.
forum Comments (0)
No comments yet. Be the first to comment.