Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-24 and was added to the RWP archive on 2026-09-07.

Daily Top · IT

StealC rode Amadey — Microsoft and Europol cut 200 C2s, not the infostealer economy

DCU 24 June 2026 — same infrastructure, two CaaS brands. 140k+ infections in the first two weeks of May. 18k victim machines Microsoft says it severed. Southern District of Florida 1:26-cv-24064.

RWP Ventures · 2026-09-07 · event 2026-06-24 · 1 min read · priority 8.2

Bottom line up front

CONFIRMED 24 June 2026 Microsoft DCU with Europol EC3, BKA, Dutch and Danish police, ESET, BitSight, Lumen, MBSD, IBM X-Force, Proofpoint — disruption of StealC and Amadey C2 domains/IPs. Microsoft: 200+ C2s via court orders, seizures, registrar/provider notices. Civil case 1:26-cv-24064-JB, SDFL. First two weeks of May: the pair linked to 140,000+ infected computers. Since the operation: 18,000+ victim machines Microsoft says it identified and severed from criminal control. Amadey is the loader; StealC is the stealer (creds, cookies, tokens, wallets). StealC language check exits on RU/UK/BY/KZ/UZ locales. Trellix Dec 2025: Amadey pulling StealC from a compromised self-hosted GitLab. Two CaaS shops, shared infra — DCU's RICO theory. Infostealer logs remain the ransomware front door. This is crimeware, not OT malware.

Historical backfill of 24 June 2026 reporting; added 7 September 2026.

What happened

A dual-family takedown because the crawler watched Amadey drop StealC on the same servers.

Why it mattered

SSO cookies from a home PC still skip MFA. Germany #2 victim share after the US (15 May–25 June) in Microsoft EMEA's telling.

Who / what was affected

Global commodity infections. Enterprises via BYOD and stealer logs (HELLCAT/Jira as the cited downstream).

Technical context

Hunt Amadey 5.x and StealC hashes from the Microsoft IOC table. Assume logs already sold. Rotate.

Exploitation / threat status at the time

CONFIRMED disruption + infection scale as Microsoft/Europol state.

ASSESSED rebuild of C2 will happen; it always does.

What defenders should have done

  1. Stealer-log monitoring for corp domains.
  2. Token binding / CAE.
  3. Do not treat "takedown" as clean.

RWP assessment

Confidence: High on the legal/tech action. Medium on lasting suppression.

Defensive actions

  1. Credential stuffing and cookie replay hunts.
  2. Block the published C2s, then watch for replacements.
  3. User devices that touch VPN are in the blast radius.

Sources

  1. Microsoft Security — StealC and Amadey
  2. Microsoft DCU — Amadey-StealC pleadings
  3. Microsoft On the Issues — Scaling cybercrime disruption