Article is online

Europol Operation Endgame Freezes €41M in Crypto, Dismantles Infostealer Networks Across Borders

Europol Operation Endgame Freezes €41M in Crypto, Dismantles Infostealer Networks Across Borders

Table of Contents




You might want to know


• How were cybercriminal networks able to siphon large sums of cryptocurrency from everyday users?


• What practical steps can individuals and platforms take now to limit exposure to infostealer malware?



Main Topic


Europol and international partners recently announced a major law enforcement action that targeted a cluster of malware families responsible for harvesting credentials and crypto wallet data from victims worldwide. The operation, conducted over a two-week period and described publicly as part of "Operation Endgame," resulted in authorities identifying and freezing more than €41 million (roughly $47 million) in criminal cryptocurrency assets. That seizure followed concerted efforts to dismantle the infrastructure used by three prominent infostealer and distribution families: SocGholish, Amadey, and StealC.



These three elements fit into a broader cybercrime-as-a-service ecosystem. Each piece plays a defined role: some provide initial access, others harvest sensitive data from infected hosts, and still others relay stolen information to criminal operators. In this takedown, law enforcement teams across multiple countries took down hundreds of servers and domains that supported these activities. Authorities reported the seizure or shutdown of 326 servers and 142 domains, and they recovered nearly 27 million stolen credentials collected from over 385,000 compromised systems. The operation also included remediation efforts for almost 15,000 infected websites, many of which belonged to small businesses that had been co-opted to serve malicious content to visitors.



StealC, one of the families singled out in the action, is an infostealer marketed as a service since 2023. It is designed to scrape saved credentials, browser cookies, and specific crypto wallet artifacts from infected machines. Notably, security researchers discovered a plugin within StealC's control panel that attempted to decrypt seed phrases for MetaMask wallets — a capability that illustrates how these tools directly target the core secrets that control crypto funds. Amadey functions largely as a dropper or access broker, gaining the initial foothold on victims' systems and delivering subsequent payloads. SocGholish, often distributed through compromised websites offering fake browser-update prompts, has been associated with the Russian-linked cybercriminal group Evil Corp and is a known mechanism for distributing additional malware to visitors of infected sites.



These operations have a real-world impact: attacks originating from this ecosystem routinely result in drained wallets, account takeovers, and follow-on fraud or extortion. Microsoft, a cooperating partner in the enforcement action, reported that Amadey and StealC were tied to over 140,000 infected machines globally during a two-week window in May. Microsoft’s Digital Crimes Unit pursued legal action under U.S. racketeering laws, treating multiple malware families as parts of a single criminal enterprise because they relied on shared infrastructure. Using AI-assisted analysis tools to study code, telemetry, and operational patterns, investigators established links that allowed them to pursue enablers across different malware operations and disrupt more than 200 command-and-control servers in prior enforcement phases.



Infostealers have become a primary channel for crypto theft because they target the precise artifacts attackers need to take control of funds: wallet files, private keys, seed phrases, and session cookies. Attack vectors are varied and often tailored to the crypto community: fake AI tools, counterfeit browser extensions, pirated game modifications, social-engineered downloads, and compromised websites serving malicious script. The approach is typically quiet and targeted — rather than running overt ransomware or noisy data exfiltration, infostealers silently collect credentials and secrets that allow attackers to empty wallets at their convenience.



The scale of exposure exposed by this and earlier phases of Operation Endgame is substantial. Prior actions uncovered login data tied to more than 100,000 crypto wallets that had been stolen but not yet emptied. This demonstrates not only the volume of data these groups can amass but also the window of opportunity criminals hold to monetize stolen assets. Law enforcement responses increasingly combine technical disruption (seizing servers and domains), legal strategies (filing civil or criminal suits under statutes like RICO), and victim notification channels (using services such as Have I Been Pwned to inform potentially affected users).



Yet takedowns are seldom terminal. Malware authors frequently adapt: operators behind StealC shipped an updated build as recently as this month, illustrating a rapid iteration cycle. The distributed and modular nature of cybercrime-as-a-service means individual components can be replaced or redeployed on new infrastructure. Therefore, while the recent action significantly disrupts specific criminal operations and freezes assets, it should be considered a meaningful but temporary blow in a longer campaign against organized, profit-driven cybercrime networks.



For users and organizations, the operation underscores the continuing need for layered defenses. Practical measures include minimizing local storage of seed phrases and private keys, enabling hardware wallets where feasible, restricting browser extensions and local credential storage, applying strict patching and content-security practices for websites, and educating users about social-engineered lures such as fake updates or counterfeit tools. On the platform side, companies can enhance detection of exfiltration patterns, block known malicious infrastructure, and partner with law enforcement and industry peers to share indicators of compromise that accelerate response and remediation.



From a policy perspective, the case highlights the value of international cooperation and the combined use of technical, legal, and public-notification tools to counter transnational cybercriminal enterprises. It also illustrates how private-sector telemetry and advanced analysis — including AI-assisted code and behavior analysis — can feed enforcement actions that dismantle the systems enabling persistent theft of digital assets.



Key Insights Table











AspectDescription
Seized AssetsMore than €41 million in criminal cryptocurrency was identified and frozen.
Targeted MalwareOperation focused on SocGholish, Amadey, and StealC — families that enable credential and wallet theft.
Infrastructure Disruption326 servers and 142 domains were taken down; over 200 C2 servers disrupted in related actions.
Data RecoveredAlmost 27 million stolen credentials from more than 385,000 compromised systems.
Ongoing RiskMalware authors update builds and can regroup; takedowns are disruptive but not permanently disabling.


Afterwards...


The Operation Endgame phase represents a significant coordinated achievement in disrupting a profitable infostealer ecosystem and limiting the immediate ability of criminals to monetize stolen crypto. Going forward, the landscape will require continued multinational law enforcement collaboration, sustained partnerships with private-sector telemetry providers, and ongoing public education to reduce the attack surface for infostealers. Users should adopt robust key management practices and organizations must prioritize rapid detection and remediation of web compromises. While the takedown reduces active infrastructure and freezes large sums of ill-gotten gains, the adaptive nature of cybercriminals means vigilance, information sharing, and layered defenses remain essential to prevent future waves of wallet theft.


Last edited at:2026/6/25
#MetaMask

Claude AI

AI Smart Editor