Visualização de leitura

Operation Endgame Disrupts SocGholish, StealC Malware Networks

Operation Endgame Disrupts SocGholish

Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware.

Led by Europol and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch ransomware attacks, financial fraud, and attacks against critical infrastructure.

Operation Endgame Targets Cybercrime Infrastructure

During the coordinated action, authorities targeted the infrastructure supporting malware delivery rather than focusing on a single malware family.

Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting malware distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.

According to Europol, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.

[caption id="attachment_112936" align="aligncenter" width="600"]Operation Endgame Image Soure: Europol[/caption] [caption id="attachment_112937" align="aligncenter" width="600"]Operation Endgame Strikes Malware Image Source: Europol[/caption]

SocGholish, Amadey and StealC Malware Played Different Roles

The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.

  • SocGholish functioned as a malware loader that distributed fake browser updates through compromised WordPress websites. Users who installed these fake updates unknowingly infected their systems, allowing attackers to gain initial access and later deploy ransomware or other malicious tools.
  • StealC malware primarily targeted sensitive information stored on infected devices, including passwords, authentication data, and digital identities. The stolen information was later used for fraud or traded within cybercriminal marketplaces.
  • Amadey was mainly distributed through phishing campaigns. It provided attackers with initial access to compromised systems while also offering information-stealing capabilities that enabled the theft of sensitive user data.

Microsoft reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.

Thousands of Infected WordPress Sites Cleaned

One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.

Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish botnet by taking control of domains and shutting down supporting servers.

Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.

The Dutch Police urged WordPress administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.

SocGholish Linked to Evil Corp

Authorities said SocGholish has been linked to Evil Corp, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.

Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.

Europol Coordinates Global Cyber Operation

Europol's European Cybercrime Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.

The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.

Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.

Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame

Operation Endgame disrupted malware services like StealC and Amadey that enable ransomware, fraud, and attacks on critical infrastructure.

Between June 15 and 19, 2026, Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK, and the US, alongside private firms like Microsoft, Bitdefender, IBM X-Force, Proofpoint, Infoblox, Shadowserver, Orange Cyberdefense, and a dozen other private partners.

The operation targeted the infrastructure behind three malware families, SocGholish, Amadey, and StealC, that together form the opening stages of the cybercrime attack chain.

“The main common goal was to disrupt the “assembly lines” cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure.” reads the report published by EUROPOL. “Crypto assets of criminal origin currently valued at over EUR 41 million (USD 47 million) were identified, flagged, and thereby restricted from use. “

The numbers from the action are substantial. Law enforcement and private partners actioned 326 servers and 142 domains, recovered 27 million stolen login credentials, and identified, flagged, and restricted over €41 million in criminal cryptocurrency assets.

During the SocGholish portion of the operation, 14,971 infected websites were remediated, including restaurants, auto repair shops, and other everyday businesses whose WordPress installations had been quietly compromised and turned into malware distribution points. The Dutch Police removed vulnerabilities from infected sites and notified owners directly.

SocGholish works by injecting fake browser update prompts into legitimate websites. A visitor clicks what looks like a routine update, and the malware installs.

“This approach, which has caused countless victims, is primarily done by hacking websites built with WordPress and infecting them with malware.” continues the report.” The unauthorised access was then exploited for further crimes, such as installing ransomware for the purpose of digital extortion.”

SocGholish is linked to Evil Corp, the Russian cybercriminal group previously responsible for Zeus and Dridex, and associated with multiple large-scale ransomware and money-laundering operations.

Amadey has been running since October 2018 as a paid dropper service, spreading primarily through phishing campaigns. It gains initial access, delivers additional malware, and also has credential and clipboard stealing capabilities. StealC, which surfaced in January 2023, is the harvesting layer: it pulls passwords, stored credentials, digital identities, and sensitive data from compromised machines and makes them available for resale and fraud.

“Amadey gains initial access to devices, while StealC extracts passwords and sensitive data.” states the report. “Together, they form a critical link in the cybercrime supply chain.”

Microsoft linked both families to over 140,000 infected computers worldwide in just the first two weeks of May 2026.

The operational logic behind targeting these three families simultaneously is what makes this phase of Operation Endgame strategically significant. Rather than focusing on the ransomware payload at the end of the chain, the operation hit the tools that make every subsequent stage possible.

“Operation Endgame targets the initial access malware used to infect devices. Cybercriminals use this malware as a gateway to silently infiltrate victims’ systems and steal sensitive data.” reads the press release published by EuroJust. “By fighting the initial stage of the attack chain, the operation strikes at the heart of the entire ‘cybercrime-as-a-service’ ecosystem.”

Take out the loader, and the ransomware operator has no foothold to monetize.

Victim notifications went out through HaveIBeenPwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and the Dutch National Cyber Security Centre. WordPress site owners whose credentials were leaked have been urged to change login credentials, enable multi-factor authentication, delete any unknown admin accounts, and keep their installations updated. For ordinary users, the advice on SocGholish is the same it’s always been and apparently still needs repeating: genuine software updates come from official sources through system settings or app stores, not from browser pop-ups that scream for immediate action.

Operation Endgame is described by Europol as the largest international operation ever undertaken to tackle ransomware enablers worldwide. More than 30 public and private parties support its actions on an ongoing basis.

The operation has an active suspect portal. The message from every law enforcement statement is consistent: each takedown raises costs, degrades operations, and generates intelligence for the next one.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Operation Endgame)

❌