Actor Profile

This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft. The operation targeted criminal infrastructure supporting the Amadey bot and StealC infostealer malware families. These malware-as-a-service (MaaS) platforms have been leveraged by multiple cybercrime actors to facilitate ransomware deployment, financial fraud, and attacks against critical infrastructure. The operation represents a coordinated public-private takedown effort rather than attribution to a specific threat actor group.

TTPs (Tactics, Techniques, Procedures)

The disrupted infrastructure supported Amadey and StealC malware operations. Amadey is a modular bot typically used for initial access and credential theft (T1555 - Credentials from Password Stores, T1539 - Steal Web Session Cookie). StealC is an information stealer focused on credential harvesting (T1555, T1005 - Data from Local System). Both malware families enable follow-on activity including ransomware deployment (T1486 - Data Encrypted for Impact), financial fraud via stolen credentials (T1078 - Valid Accounts), and potential access to critical infrastructure environments. The recovery of 27 million credentials indicates extensive data exfiltration capabilities (T1041 - Exfiltration Over C2 Channel).

Targets & Patterns

The infrastructure disrupted in this operation facilitated attacks across multiple sectors. While no specific targeted sectors are identified, the operation's scope indicates broad victimology. The malware families supported ransomware operations, financial fraud campaigns, and attacks on critical infrastructure, suggesting opportunistic targeting rather than sector-specific focus. The volume of 27 million stolen credentials indicates widespread compromise across enterprise and consumer environments globally. The MaaS model employed by these malware families enables diverse threat actors to target victims based on their individual objectives.

Historical Context

Amadey has been active as a malware-as-a-service platform since at least 2018, frequently observed as an initial access vector in multi-stage infection chains leading to ransomware deployment. StealC emerged in the infostealer landscape more recently and has been marketed on underground forums as a credential theft tool. Both malware families represent commoditized criminal infrastructure available to multiple threat actors. This disruption operation follows a pattern of coordinated law enforcement and private sector takedowns targeting malware infrastructure, similar to operations against Emotet, TrickBot, and other botnet networks in recent years.

Defensive Recommendations

  • Monitor for indicators of Amadey and StealC malware, including command-and-control domains and file hashes shared by Europol and partner organizations
  • Implement credential monitoring services to detect if organizational credentials appear in the 27 million recovered records and force password resets where necessary
  • Deploy endpoint detection rules for infostealer behavior patterns including browser credential access (T1555.003), cookie theft (T1539), and data staging activities (T1074)
  • Harden initial access vectors by blocking known malicious infrastructure, implementing email security controls to prevent malware delivery, and restricting PowerShell execution (T1059.001) where not required
  • Enable multi-factor authentication across all services to mitigate risk from stolen credentials and monitor for anomalous authentication patterns indicating credential abuse (T1078)