Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-24 and was added to the RWP archive on 2026-09-07.
StealC rode Amadey — Microsoft and Europol cut 200 C2s, not the infostealer economy
DCU 24 June 2026 — same infrastructure, two CaaS brands. 140k+ infections in the first two weeks of May. 18k victim machines Microsoft says it severed. Southern District of Florida 1:26-cv-24064.
Bottom line up front
CONFIRMED 24 June 2026 Microsoft DCU with Europol EC3, BKA, Dutch and Danish police, ESET, BitSight, Lumen, MBSD, IBM X-Force, Proofpoint — disruption of StealC and Amadey C2 domains/IPs. Microsoft: 200+ C2s via court orders, seizures, registrar/provider notices. Civil case 1:26-cv-24064-JB, SDFL. First two weeks of May: the pair linked to 140,000+ infected computers. Since the operation: 18,000+ victim machines Microsoft says it identified and severed from criminal control. Amadey is the loader; StealC is the stealer (creds, cookies, tokens, wallets). StealC language check exits on RU/UK/BY/KZ/UZ locales. Trellix Dec 2025: Amadey pulling StealC from a compromised self-hosted GitLab. Two CaaS shops, shared infra — DCU's RICO theory. Infostealer logs remain the ransomware front door. This is crimeware, not OT malware.
Historical backfill of 24 June 2026 reporting; added 7 September 2026.
What happened
A dual-family takedown because the crawler watched Amadey drop StealC on the same servers.
Why it mattered
SSO cookies from a home PC still skip MFA. Germany #2 victim share after the US (15 May–25 June) in Microsoft EMEA's telling.
Who / what was affected
Global commodity infections. Enterprises via BYOD and stealer logs (HELLCAT/Jira as the cited downstream).
Technical context
Hunt Amadey 5.x and StealC hashes from the Microsoft IOC table. Assume logs already sold. Rotate.
Exploitation / threat status at the time
CONFIRMED disruption + infection scale as Microsoft/Europol state.
ASSESSED rebuild of C2 will happen; it always does.
What defenders should have done
- Stealer-log monitoring for corp domains.
- Token binding / CAE.
- Do not treat "takedown" as clean.
RWP assessment
Confidence: High on the legal/tech action. Medium on lasting suppression.
Defensive actions
- Credential stuffing and cookie replay hunts.
- Block the published C2s, then watch for replacements.
- User devices that touch VPN are in the blast radius.
Sources
- Microsoft Security — StealC and Amadey
- Microsoft DCU — Amadey-StealC pleadings
- Microsoft On the Issues — Scaling cybercrime disruption