Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Operation Endgame disrupts three major malware networks

Operation Endgame targeted 326 servers and 142 domains linked to SocGholish, Amadey and StealC. What the action achieved and defenders should do.

PUBLIC RESEARCH
AUTHOR
/ Penetration Tester (OSCP, PNPT)
PUBLISHED
10 July 2026
READING TIME
9 min read
TOPIC
Malware
Operation Endgame disrupts three major malware networks

On 24 June 2026, Europol summarised another phase of Operation Endgame, an international effort targeting tools that provide initial access rather than one ransomware brand. This phase focused on three parts of the cybercrime supply chain: SocGholish, Amadey and StealC.

According to Europol, actions covered 326 servers and 142 domains, approximately 27 million stolen credentials were recovered, and more than €41 million in crypto assets were identified, marked and restricted. The strategic point is as important as the numbers: law enforcement acted near the beginning of attack chains, before a loader or infostealer could enable ransomware.

Three malware families, three roles

SocGholish, also known as FakeUpdates, abuses compromised legitimate websites. Visitors see a fake browser or software update. Running it installs a loader that provides access and delivers additional malware. Europol connects SocGholish with the Russian cybercrime group Evil Corp.

Amadey is also a loader. It spreads through channels including phishing, downloads additional components and can steal information useful for reconnaissance.

StealC is primarily an infostealer. It collects browser passwords, session tokens and digital identities, then sends them to criminals. The data can be sold or used to enter company networks. In the first two weeks of May 2026, Microsoft data cited by Europol linked Amadey and StealC with more than 140,000 infected computers worldwide. That number is not a victim count for one police action.

Why disrupting initial-access suppliers matters

Modern attacks are often delivered as a service chain. One operator infects devices, another steals credentials, an access broker sells entry, and a ransomware affiliate performs the final extortion. Loaders and infostealers are shared infrastructure for many later crimes.

Disrupting several tools simultaneously increases cost throughout that market. Operators lose servers and domains, customers lose delivery channels, and recovered credentials can support victim notification. This complements ransomware defence by interrupting the chain before file encryption.

14,971 cleaned WordPress sites

The SocGholish action had a visible website component. Europol and Dutch police reported cleaning 14,971 infected sites, including restaurants, workshops and other small businesses. Authorities removed malware and backdoors, took control of botnet domains and notified owners.

Dutch police also said the analysed data contained exposed credentials associated with about 1.4 million WordPress sites. That does not mean every site was infected. It represents a large pool of potential targets that could be attacked with valid or reused credentials.

Administrators should change privileged credentials, enable MFA, remove unknown accounts, update core/plugins/themes, and inspect files and configuration for persistence. A password change alone is inadequate if an attacker already added an account or backdoor. Apply the controls in our WordPress security guide.

What users and companies should do

Install browser and software updates through the operating system, official store or application’s built-in mechanism—not a pop-up on a random website.

Organisations should also:

  • block execution from unusual download locations;
  • monitor session-token and credential theft, not only malware file detections;
  • reset secrets used on an infected workstation;
  • isolate hosts after an infostealer detection;
  • review subsequent logins and device registrations;
  • activate a prepared incident-response process.

If an infostealer ran on a computer, assume that every account used during the infection may be exposed, not only one password mentioned in an alert.

Did Operation Endgame end the threat?

No. The announcement supports a conclusion of infrastructure disruption and increased friction—not the complete destruction of Evil Corp, every malware variant or the initial-access market. Criminals may rebuild infrastructure or switch tools. The June summary also did not announce a new arrest covering all three families.

For defenders, the lesson is practical: a fake update, compromised WordPress site or single infostealer alert can be the beginning of a full intrusion. Respond before the access is transferred to the next criminal.


Sources: Europol, 24 June 2026, Dutch police on SocGholish, Dutch police on Amadey and StealC.

SHARE / COPY