Between June 15–19, 2026, Operation Endgame dismantled the criminal infrastructure behind the SocGholish malware loader, the Amadey botnet, and the StealC infostealer — seizing 326 servers, 142 domains, 27 million sto... Key results: 326 servers and 142 domains taken down; nearly 15,000 websites remediated; over €41...
Research answer

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What cybercrime infrastructure was dismantled in Operation Endgame between June 15-19, 2026, whic. Article summary: Between June 15–19, 2026, Operation Endgame dismantled the criminal infrastructure behind the **SocGholish** malware loader, the **Amadey** botnet, and the **StealC** infostealer — targeting the early-stage supply chain . Topic tags: general, government, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, ch
Between June 15–19, 2026, a coordinated international law enforcement operation dismantled the criminal infrastructure driving three major malware strains that have enabled ransomware attacks, data theft, and financial fraud at scale. Operation Endgame, coordinated by Europol and Eurojust, targeted the SocGholish malware loader, the Amadey botnet, and the StealC infostealer — disrupting the early-stage supply chain that cybercriminals depend on to launch ransomware attacks worldwide .
The takedown achieved significant metrics across multiple dimensions:
Each malware strain played a distinct role in the cybercrime ecosystem:
SocGholish is a widely used malware loader that injects malicious JavaScript into compromised websites, primarily WordPress sites. It operates as an initial-access broker for ransomware operations, including affiliates of the Evil Corp cybercriminal group . Dutch police announced the SocGholish takedown days before the broader operation targeting Amadey and StealC was revealed
.
Amadey is a botnet and malware loader that functions as a delivery mechanism for second-stage payloads, including StealC. Developed by separate criminal groups, Amadey and StealC work in tandem to compromise devices and harvest sensitive data .
StealC is an infostealer sold as a service (Stealer-as-a-Service) to other cybercriminals. It specializes in stealing credentials, browser data, and other sensitive information from infected machines . According to Proofpoint and IBM X-Force, who provided technical intelligence, the June operation specifically affected 66 StealC domains
.
The operation involved an unprecedented level of international cooperation:
Law enforcement agencies: Canada (RCMP), Denmark, Germany (BKA and the Frankfurt Cybercrime Center ZIT), the Netherlands (National Police), the United Kingdom (National Crime Agency), the United States (FBI), Europol, and Eurojust .
Private-sector partners: Microsoft (Digital Crimes Unit), Bitdefender, IBM X-Force, Proofpoint, Infoblox, the Shadowserver Foundation, Orange Cyberdefense, Bitsight, and ESET .
Operation Endgame represents a clear strategic shift in how law enforcement combats cybercrime. Rather than pursuing individual ransomware groups after attacks occur, this operation targeted the cybercrime supply chain at its foundation — the loaders, infostealers, and initial-access brokers that enable mass compromise .
Europol describes this as a "landmark blow to cybercriminal networks" that weakens the entire criminal value chain . By simultaneously targeting SocGholish, Amadey, and StealC, authorities severed the delivery mechanisms that multiple ransomware affiliates depend on, breaking what the BKA called the "virtual infection chain" and preventing further victim infections before ransomware is ever deployed
. The official Operation Endgame website described the common goal as disrupting the "assembly lines" cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure
.
The BKA press release reports figures rounded to "over 320 servers and more than 140 domains" , while Europol and other sources report exact counts of 326 servers and 142 domains
. These figures are consistent within standard rounding conventions and do not materially change the assessed scale of the takedown.
This is the latest action in Operation Endgame, which launched in May 2024 as a sustained campaign against botnets and dropper malware. Previous phases targeted malware including Qakbot, Bumblebee, DanaBot, Trickbot, and others , and a November 2025 phase took down the Rhadamanthys infostealer, VenomRAT, and Elysium botnet
.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Between June 15–19, 2026, Operation Endgame dismantled the criminal infrastructure behind the SocGholish malware loader, the Amadey botnet, and the StealC infostealer — seizing 326 servers, 142 domains, 27 million sto...
Between June 15–19, 2026, Operation Endgame dismantled the criminal infrastructure behind the SocGholish malware loader, the Amadey botnet, and the StealC infostealer — seizing 326 servers, 142 domains, 27 million sto... Key results: 326 servers and 142 domains taken down; nearly 15,000 websites remediated; over €41 million / $47 million in criminal crypto frozen; 27 million stolen credentials recovered from 385,000+ victims; over 140...