Back to the desk

News briefing

Operation Endgame takes down 326 servers behind SocGholish, StealC and Amadey

Severity: HighGlobalLaw enforcement2026-0624-OE02 min readBy Vivek Kumar
Conceptual illustration: server racks beside a large power symbol. Text: OPERATION ENDGAME.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

A 15-19 June 2026 action week coordinated by Europol and Eurojust disrupted three malware families that feed ransomware and fraud, recovering about 27 million stolen credentials and securing over EUR 41 million in crypto.

01 / What happened

Europol and Eurojust announced on 24 June 2026 that the latest phase of Operation Endgame had disrupted infrastructure behind three malware families: the SocGholish loader, the StealC information stealer and the Amadey dropper. The action week ran from 15 to 19 June 2026.

According to Eurojust, authorities neutralised 326 servers and 142 domains and recovered 27 million compromised data sets. Europol said more than EUR 41 million in criminal cryptocurrency was seized. No arrests were announced for this phase.

Eurojust named participating authorities from Germany (including the BKA, the ZIT cybercrime unit in Frankfurt and the BSI), Denmark, France, the Netherlands, the United Kingdom's National Crime Agency, the United States and Canada. Europol's release also lists Australia and Belgium, alongside more than 30 private-sector partners including Microsoft, Proofpoint, Shadowserver and Have I Been Pwned.

02 / Why it matters

The three targets sit at the start of the attack chain. SocGholish, also known as FakeUpdates, lures visitors of compromised websites, many running WordPress, into installing fake browser updates. Amadey spreads through phishing and installs further malware, while StealC harvests passwords and digital identities for resale.

Removing the delivery layer makes every downstream ransomware and fraud operation more expensive to run.

Eurojust describes Operation Endgame as a long-running effort against the initial-access malware that underpins cybercrime-as-a-service. BleepingComputer notes that operators often rebuild infrastructure when takedowns are not accompanied by arrests, so the durability of this disruption is not yet clear.

03 / Who is exposed

A private-sector partner in the operation, cited by BleepingComputer, linked Amadey and StealC to more than 140,000 infected devices in the first two weeks of May 2026 alone. Groups at risk include:

  • Users whose browser-stored passwords or session data were taken by StealC.
  • Owners of websites that were compromised to serve SocGholish fake-update prompts.
  • Organisations whose staff credentials appear in the recovered data and may be sold on to ransomware affiliates.

Have I Been Pwned loaded the data as the Operation Endgame 4.0 breach, covering 4.3 million unique email addresses.

04 / Confirmed vs. claimed

Confirmed by Eurojust and Europol: the 15-19 June dates, 326 servers, 142 domains, 27 million recovered data sets, over EUR 41 million in seized crypto. Reported by BleepingComputer, citing Europol, but not in the Eurojust release this desk read: that the credentials came from more than 385,000 compromised systems. The 140,000-infection figure comes from a private partner, not from law enforcement. Whether any suspects have been identified or charged has not been disclosed.

05 / What to do now

  • Check corporate domains against the Have I Been Pwned Operation Endgame 4.0 data and force password resets for matches.
  • Revoke active sessions and tokens for affected users, since stealers often capture cookies as well as passwords.
  • Block or alert on browser-update prompts delivered by websites, and restrict script execution from user download folders.
  • Website owners should patch CMS plugins and scan for injected JavaScript linked to SocGholish.
  • Discourage storing work passwords in browsers and adopt a managed password manager with phishing-resistant MFA.

Source log / 2026-0624-OE

More from the archive