Operation Endgame targeted infrastructure linked to SocGholish, Amadey and StealC, with authorities seizing about $47 million in illicit cryptocurrency and recovering more than 27 million stolen credentials.
Europol said a joint Operation Endgame action with law enforcement agencies from Canada, Denmark, Germany, the Netherlands and the U.S. targeted cybercrime infrastructure tied to the SocGholish, Amadey and StealC malware services. Authorities acted against 326 servers and 142 domains, seized about $47 million in illegal cryptocurrency and recovered more than 27 million stolen credentials. The action expands on an earlier account of the crackdown that said 41 million euros in crypto assets had been frozen and highlighted StealC's offering of a MetaMask seed phrase decryption plugin, underscoring the operation's relevance to wallet theft and data-harvesting malware.