27 Million Credentials Recovered from Amadey and StealC Malware Network

Amadey and StealC, two big components of a larger Malware-as-a-Service infrastructure, were recently taken down as part of a coordinated law enforcement operation. The malware network first surfaced in 2018 with Amadey, a trojan loader that allows next-stage malware such as information stealers to gain access to a system. This is where StealC comes in. As an infostealer, threat actors can pair it with loaders like Amadey for easy data harvesting. The operation mainly took place through WordPress hosted sites and other phishing campaigns, and stole upwards of 27 million credentials in just a few years. However, on June 24, 2026, just days after another malware SocGholish was exposed, law enforcement partnered with private sector companies to take down the cybercriminals; criminal assets valued at more than 47 million dollars as well as those 27 million credentials were recovered. The takedown was made possible by exploiting a vulnerability in the web-based StealC control panel. "[According to] Alex Cosoi, chief security strategist at Bitdefender, 'This takedown is a powerful demonstration of what public and private sector collaboration can achieve in dismantling the infrastructure that enables cybercrime at scale.'"