Operation Endgame Freezes $47M in Crypto, Dismantles Malware Families
A global law enforcement operation, Operation Endgame, has frozen over €41 million ($47 million) in criminal cryptocurrency assets, Europol announced on Wednesday. The two-week multi-country strike dismantled the infrastructure behind three malware families: SocGholish, Amadey, and StealC, which are used to steal passwords and crypto wallet data, fueling fraud and ransomware. Police took down 326 servers and 142 domains, recovered nearly 27 million stolen credentials from more than 385,000 infected systems, and cleaned almost 15,000 infected websites. Microsoft, a partner in the operation, linked Amadey and StealC to over 140,000 infected computers in early May alone. The operation also included a U.S. racketeering lawsuit filed by Microsoft's Digital Crimes Unit, which treated the two malware families as a single criminal conspiracy and disrupted over 200 command-and-control servers. This is part of ongoing efforts to combat cybercrime-as-a-service, where infostealers like StealC target crypto users by scraping passwords, cookies, wallet data, and even attempting to decrypt MetaMask seed phrases. Despite the takedown, operators often regroup, and StealC has released a new version this month. Europol is directing victims to services like Have I Been Pwned to check if their credentials are compromised.
Key facts
- Freeze of €41M+ ($47M) in criminal crypto assets.
- Dismantled infrastructure of SocGholish, Amadey, and StealC malware.
- Seized 326 servers and 142 domains; recovered 27M credentials.
- StealC scrapes wallet data, including MetaMask seed phrases.
- Microsoft filed RICO lawsuit targeting the malware ecosystem.
KeyAudit data perspective
🔧 Check your seed against KeyAudit leak DB