U.S. — Microsoft, law enforcement agencies, and cybersecurity companies collaborated in May 2026 to take down infrastructure shared by the Amadey and StealC malware families. This operation, known as Operation Endgame, involved the use of artificial intelligence, legal actions, and the exploitation of a vulnerability in a malware control panel.

Europol stated the operation disrupted 326 servers and 142 domains. More than 25 million unique credentials, stolen from over 385,000 systems, were seized, and 18,000 compromised computers were identified and secured. Europol also stated that crypto assets valued at more than $47 million were identified and flagged to restrict their use.

Researchers discovered a vulnerability in the StealC command-and-control panel, which enabled uploading a web shell to the server. AI-powered analysis confirmed that Amadey and StealC utilized the same command-and-control infrastructure. Microsoft's Digital Crimes Unit identified over 200 malicious command-and-control domains and IP addresses associated with both malware families.

Microsoft filed a civil action in the U.S. regarding the Amadey and StealC infrastructure. The company reported that the malware families were linked to more than 140,000 infected devices during the first two weeks of May 2026. ESET reported that the action impacted approximately 50 domains used by the operations and nearly 200 active command-and-control servers.

Europol and Eurojust coordinated the Operation Endgame effort, which included law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States. Private-sector support was provided by Microsoft, ESET, Proofpoint, IBM X-Force, Bitsight, Infoblox, Orange Cyberdefense, Shadowserver, and Have I Been Pwned. Several organizations involved, including Microsoft, Europol, ESET, Bitsight, IBM X-Force, Proofpoint, and Mitsui Bussan Secure Directions, published blog posts describing the actions taken.

Europol characterized the operation as a strategic shift. "This operation marked a shift in strategy: instead of focusing solely on individual threats, Europol, law enforcement and judicial authorities, as well as private industry partners disrupted the entire chain that allows cyberattacks to scale," the agency said. It added, "By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cybercriminals, making it harder for attacks to succeed, spread, or recover."

Amadey, a malware-as-a-service loader, has been active since 2018. StealC, an infostealer, has been active since 2023.