Operation Endgame disrupts Amadey and Stealc
ESET Research contributed to a global disruption operation targeting the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings. The operation, coordinated by Microsoft Digital Crimes Unit, BitSight, Lumen, and MBSD, impacted approximately 50 domains and nearly 200 active IP-based command and control servers. ESET provided technical analyses, statistical information, C&C server lists, encryption keys, campaign identifiers, and affiliate-level insights gathered from three years of tracking. Both malware families operate through affiliate networks where operators deploy their own infrastructure, making disruption efforts particularly challenging. Amadey primarily functions as a modular loader distributing additional payloads, while Stealc focuses on credential theft from browsers, crypto wallets, and applications. The largest Amadey botnet cluster accounted for 34% of all samples and distributed an average of 14 payloads per victim, operating a pay-per-install model that monetized compromi...
AI Analysis
Technical Summary
Operation Endgame targeted and disrupted the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings that rely on affiliate networks for deployment. The operation, coordinated by multiple organizations including Microsoft Digital Crimes Unit and ESET Research, took down approximately 50 domains and nearly 200 IP-based command and control servers. Amadey functions primarily as a modular loader distributing an average of 14 payloads per victim and operates on a pay-per-install model. Stealc focuses on credential theft from browsers, crypto wallets, and applications. The disruption leveraged three years of tracking data including encryption keys and campaign identifiers. Due to the decentralized affiliate model, disruption efforts were challenging but impactful.
Potential Impact
The operation disrupted the infrastructure of two active malware-as-a-service platforms, Amadey and Stealc, reducing their ability to distribute payloads and steal credentials. This disruption affected approximately 50 domains and nearly 200 command and control servers, thereby limiting ongoing malicious activity. No direct exploits or vulnerabilities in legitimate software were involved. The impact is primarily on the malware operators and their affiliates, reducing their operational capacity.
Mitigation Recommendations
This is a law enforcement and industry-coordinated disruption operation targeting malware infrastructure. No direct patch or software fix applies. Organizations should continue to apply standard security practices to defend against malware infections. The disruption reduces current threat activity from these malware families. Patch status is not applicable. No further immediate action is required based on this disruption report.
Indicators of Compromise
- ip: 176.124.199.207
- ip: 176.111.174.140
- hash: ff8d2afd9d7f0a828592fee34ca55d1a3542f7ed
- ip: 62.60.226.159
- ip: 94.154.35.25
- domain: mi.overlapsnowbound.com
- ip: 64.188.91.237
- ip: 196.251.107.130
- ip: 193.143.1.16
- ip: 95.85.238.4
- hash: 09002d4668a778853e8da5c488c6e421c0628357
- hash: 11a42ef076686cb27ba2c8845301943652a5aadc
- hash: 32d0c3300825b0bb991c4a8f1e6244f0ad2da989
- hash: 38d744543b2051e6f749af171b5ef8d6df8aac7b
- hash: 5f3f99b14243404c7cf57b40bb101244cce394bf
- hash: 87867ad29e621bf9ebf57e1757f75090842458be
- hash: b4101027bf2f1261402bf6318c6eb016ce249037
- hash: c0e178d26e1e67985a9c67e649d71d54642e0eed
- hash: f61e3a643f2417e1a1ab2c83bbdbfc8a7cb96756
Operation Endgame disrupts Amadey and Stealc
Description
ESET Research contributed to a global disruption operation targeting the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings. The operation, coordinated by Microsoft Digital Crimes Unit, BitSight, Lumen, and MBSD, impacted approximately 50 domains and nearly 200 active IP-based command and control servers. ESET provided technical analyses, statistical information, C&C server lists, encryption keys, campaign identifiers, and affiliate-level insights gathered from three years of tracking. Both malware families operate through affiliate networks where operators deploy their own infrastructure, making disruption efforts particularly challenging. Amadey primarily functions as a modular loader distributing additional payloads, while Stealc focuses on credential theft from browsers, crypto wallets, and applications. The largest Amadey botnet cluster accounted for 34% of all samples and distributed an average of 14 payloads per victim, operating a pay-per-install model that monetized compromi...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Operation Endgame targeted and disrupted the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings that rely on affiliate networks for deployment. The operation, coordinated by multiple organizations including Microsoft Digital Crimes Unit and ESET Research, took down approximately 50 domains and nearly 200 IP-based command and control servers. Amadey functions primarily as a modular loader distributing an average of 14 payloads per victim and operates on a pay-per-install model. Stealc focuses on credential theft from browsers, crypto wallets, and applications. The disruption leveraged three years of tracking data including encryption keys and campaign identifiers. Due to the decentralized affiliate model, disruption efforts were challenging but impactful.
Potential Impact
The operation disrupted the infrastructure of two active malware-as-a-service platforms, Amadey and Stealc, reducing their ability to distribute payloads and steal credentials. This disruption affected approximately 50 domains and nearly 200 command and control servers, thereby limiting ongoing malicious activity. No direct exploits or vulnerabilities in legitimate software were involved. The impact is primarily on the malware operators and their affiliates, reducing their operational capacity.
Defensive Guidance
This is a law enforcement and industry-coordinated disruption operation targeting malware infrastructure. No direct patch or software fix applies. Organizations should continue to apply standard security practices to defend against malware infections. The disruption reduces current threat activity from these malware families. Patch status is not applicable. No further immediate action is required based on this disruption report.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"]
- Adversary
- null
- Pulse Id
- 6a3c278cadbc5a0ba0a18ce3
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip176.124.199.207 | — | |
ip176.111.174.140 | — | |
ip62.60.226.159 | — | |
ip94.154.35.25 | — | |
ip64.188.91.237 | — | |
ip196.251.107.130 | — | |
ip193.143.1.16 | — | |
ip95.85.238.4 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashff8d2afd9d7f0a828592fee34ca55d1a3542f7ed | — | |
hash09002d4668a778853e8da5c488c6e421c0628357 | — | |
hash11a42ef076686cb27ba2c8845301943652a5aadc | — | |
hash32d0c3300825b0bb991c4a8f1e6244f0ad2da989 | — | |
hash38d744543b2051e6f749af171b5ef8d6df8aac7b | — | |
hash5f3f99b14243404c7cf57b40bb101244cce394bf | — | |
hash87867ad29e621bf9ebf57e1757f75090842458be | — | |
hashb4101027bf2f1261402bf6318c6eb016ce249037 | — | |
hashc0e178d26e1e67985a9c67e649d71d54642e0eed | — | |
hashf61e3a643f2417e1a1ab2c83bbdbfc8a7cb96756 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainmi.overlapsnowbound.com | — |
Threat ID: 6a3d46404853345fc11c395a
Added to database: 06/25/2026, 15:16:16 UTC
Last enriched: 07/31/2026, 12:46:43 UTC
Last updated: 08/09/2026, 05:53:13 UTC
Views: 125
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.