Global Operation Disrupts Major Cybercrime Tools Amadey and StealC
International authorities and major technology companies are disrupting a cybercrime "assembly line" that allows criminals to collect millions of login credentials and steal over $47 million through ransom payments and fraud. The coordinated effort, known as Operation Endgame, simultaneously targets two widely used malicious platforms that play critical roles in the online crime ecosystem.
The first tool, Amadey, operates as a malware-as-a-service platform that compromises devices and delivers malicious payloads for ransomware and other scams. The second tool, StealC, functions as an infostealer that collects credentials, authentication cookies, cryptocurrency wallets, and sensitive files. While the tools run independently, many cybercriminals use both in tandem, with Amadey gaining device access and StealC harvesting valuable data.
Microsoft uses AI analysis to discover that both tools rely on some of the same underlying infrastructure. This insight enables Microsoft attorneys to invoke RICO statutes designed to target organized crime, treating both platforms as part of a single conspiracy. The legal strategy allows authorities to disrupt both operations simultaneously, striking what Microsoft calls a critical link in the cybercrime chain.