Operation Endgame has struck another major blow against global cybercrime after international authorities dismantled infrastructure used by three of the world’s most active malware families. The coordinated operation disrupted services that helped cybercriminals launch ransomware attacks, steal credentials, and compromise organizations worldwide. Investigators also recovered millions of stolen passwords and identified cryptocurrency linked to criminal operations.
International Operation Targets Malware Infrastructure
Law enforcement agencies from six countries joined forces with Europol, Eurojust, Microsoft, and several cybersecurity companies to dismantle cybercriminal infrastructure between June 15 and June 19, 2026.
During the operation, investigators disabled approximately 15,000 malicious websites, more than 320 servers, and 140 domains that supported criminal activity. Authorities also seized around 27 million stolen login credentials belonging to more than 385,000 victims.
Investigators identified approximately $47 million in cryptocurrency believed to be connected to cybercrime. The funds are now part of ongoing investigations as authorities continue tracing criminal networks.
Officials are also contacting affected victims whose credentials were recovered during the operation.
Operation Endgame Focused on Initial Access Malware
The latest phase of Operation Endgame targeted the infrastructure behind three widely used malware families: SocGholish, StealC, and Amadey.
Security agencies describe these malware strains as critical tools within the cybercrime ecosystem because they provide attackers with initial access to victim systems. Once access is established, cybercriminals frequently deploy ransomware, steal sensitive information, or install additional malicious software.
By disrupting these entry points, investigators hope to reduce the number of successful ransomware attacks before they begin.
German officials described the operation as an effort to break the cybercriminal kill chain at its earliest stage.
Malware-as-a-Service Continues to Fuel Cybercrime
All three malware families operated under a Malware-as-a-Service model, allowing criminals with limited technical knowledge to purchase sophisticated attack capabilities.
SocGholish spreads through compromised websites that display fake browser update prompts. Victims who download the fraudulent updates unknowingly install malware on their devices.
StealC specializes in stealing passwords, authentication tokens, and other sensitive information. The malware can also function as a loader that installs additional malicious payloads after compromising a system.
Amadey commonly spreads through phishing emails and malicious attachments. Once executed, it can download other malware while simultaneously collecting passwords and sensitive information from infected devices.
Stolen credentials often appear on underground marketplaces or become the starting point for larger cyberattacks.
International Cooperation Remains Essential
Officials involved in the investigation praised the coordinated effort between law enforcement agencies and private industry.
German authorities said the operation prevented countless future infections by removing infrastructure that many cybercriminal groups depended on.
Prosecutors also emphasized that international collaboration remains one of the strongest tools available against increasingly global cybercrime operations. Criminal groups routinely operate across multiple jurisdictions, making coordinated investigations essential for disrupting their activities.
The participation of technology companies alongside law enforcement demonstrates how public and private organizations continue working together to combat large-scale cyber threats.
Conclusion
Operation Endgame represents another significant success in the global effort to disrupt cybercrime before ransomware attacks begin. By dismantling the infrastructure supporting SocGholish, StealC, and Amadey, investigators removed key tools that enable attackers to gain initial access to victim networks. The seizure of 27 million stolen passwords and millions of dollars in suspected criminal cryptocurrency highlights both the scale of modern cybercrime and the growing effectiveness of international cooperation against it.


0 responses to “Operation Endgame Seizes 27 Million Passwords in Malware Crackdown”