Threats

Microsoft Tackles Amadey and StealC Cybercrime Tools

June 25, 2026 04:18 · 12 min read
Microsoft Tackles Amadey and StealC Cybercrime Tools

Joint Operation Targets Amadey and StealC Cybercrime Tools

Microsoft has announced a novel approach to disrupting cyber attackers, teaming up with law enforcement to take down two widely-used criminal tools, Amadey and StealC, simultaneously. This operation marks a significant shift in strategy, as the industry and law enforcement have traditionally targeted individual threats rather than tackling multiple tools at once.

According to Microsoft, Amadey is a botnet that can serve as a malware delivery system, while StealC is an infostealer that collects sensitive data from various sources. Cybercriminals often use these tools in conjunction, and they rely on the same infrastructure, making them an attractive target for disruption.

Collaborative Effort

Microsoft had been tracking Amadey with the help of ESET, BitSight, Lumen, and Mitsui Bussan Secure Directions. Meanwhile, Europol had been investigating StealC alongside law enforcement partners, including Germany's Federal Criminal Police Office and the Dutch and Danish National Police, as well as IBM X-Force and Proofpoint.

The joint operation used the Racketeer Influenced and Corrupt Organizations (RICO) Act to disrupt over 200 command-and-control servers. Microsoft's artificial intelligence product, Copilot, played a crucial role in providing insights that allowed the legal team to treat both malware families as part of a single criminal conspiracy.

Impact of the Takedown

The takedown has significant implications for cybercrime, as Amadey and StealC were linked to over 140,000 infected computers worldwide in the first week of May alone. StealC has been ranked among the top infostealers for years, and its emergence in 2023 marked a new era in malware-as-a-service offerings. Amadey, on the other hand, dates back to 2018 and has been commonly employed by Russian groups, including in attacks on Ukraine.

According to Steven Masada, assistant general counsel for Microsoft's Digital Crimes Unit,

When multiple parts of an operation are disrupted together, attacks are harder to launch, scale, and recover from. The result: fewer disrupted services, fewer opportunities for cybercriminals to profit, and more friction when they try to rebuild.

Modular Cybercrime Models

The interaction between Amadey and StealC demonstrates the assembly line-like structure of modern cybercrime. Even if the cybercriminals behind both tools never coordinate, their tools are designed to work together seamlessly. This modular approach allows threat actors to use a single initial infection to quickly escalate into multiple other threats.

As Microsoft noted in a separate blog post, StealC is an infostealer that collects sensitive data from browsers, cryptocurrency wallets, messaging applications, email clients, and gaming platforms. It is a malware-as-a-service (MaaS) offering that threat actors use to generate customized payloads and manage stolen data through a centralized web panel. Meanwhile, Amadey is a MaaS loader that threat actors use to deliver StealC and other malware.

Conclusion

The joint operation to take down Amadey and StealC marks a significant milestone in the fight against cybercrime. By targeting multiple tools simultaneously, the industry and law enforcement can create more friction for cybercriminals, making it harder for them to launch and scale their attacks. As the cybercrime landscape continues to evolve, it is essential to adopt a collaborative and proactive approach to disruption operations.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free