Global operation to unload MaaS Amadey and StealC networks: 47 million in assets and 27 million credentials recovered

Author: Published 4 min de lectura 164 reading

The images in this article were generated with artificial intelligence. How we publish

A coordinated operation between security forces and private companies, with the participation of companies such as Bitdefender, Bitsight, ESET and Microsoft, has neutralized a significant part of the criminal infrastructure that fed the ecosystems of malware Amadey and StealC. According to the authorities, the action allowed to identify and restrict cryptographic assets for more than $47 million, recover until 27 million stolen credentials and dismantle hundreds of servers and dozens of domains that served as command and control centers.

The case is a clear picture of the economic model that supports modern cybercrime: Malware- as- a- service (MaaS) services offer customers and affiliates "assembly lines" to launch financial fraud, ransomware and identity theft campaigns. Amadey, StealC and loaders such as SocGholish or SmokeLoader operate in that chain as interchangeable parts: the loaders open the door and the stealers are in charge of the information being extracted and monetized. The documented commercial prices and models - licenses, rates for rebuilds or monthly subscriptions - explain why this market is persistent and scalable.

Global operation to unload MaaS Amadey and StealC networks: 47 million in assets and 27 million credentials recovered
Image generated with IA.

From the technical point of view, Amadey and StealC show advanced and modular capabilities: system footprint collection, download and execution of DLLs, EXE or scripts, screen capture, card removal and cookies from browsers and desktop applications (Discord, FileZilla, Outlook, Telegram, among others), creation of SOCKS connections, remote control via VNC or RDP and steps to avoid infecting certain countries. These functions turn an initial infection into a vector for lateral movement, exfiltration and access sale in clandestine markets.

The operation shows that public-private cooperation can interrupt these criminal supply chains, but it does not eliminate the problem of substance: actors change infrastructure, rotate affiliates and exploit new service providers. In addition, jurisdictional complexities, the speed of the rotation of domains and the economy behind organized crime mean that dismantling must be combined with financial follow-up, sustained legal action and international cooperation to be truly dissuasive. The work of cryptographic asset mapping and the closure of control panels degrade capacities, but the resilience of the ecosystem requires permanent monitoring.

For organizations, the lesson is practical and urgent: to protect the initial access phase reduces the likelihood of greater commitments. This includes keeping CMS and components up-to-date (WordPress, plugins and themes), applying strong password policies and multifactor authentication, deploying modern EDR / AV solutions with behavior detection, segmenting networks to limit lateral movement, and setting up outbound registration and monitoring to detect known C2 connections. Having proven incident response procedures, off-line backup and collaboration channels with suppliers and law enforcement forces accelerates containment when an intrusion is detected. Guidelines and public resources can help prioritize actions: see the recommendations of cyber security agencies such as CISA and mapping tactics and techniques to frameworks such as MITRE ATT & CK to design effective detections.

Global operation to unload MaaS Amadey and StealC networks: 47 million in assets and 27 million credentials recovered
Image generated with IA.

For users and website administrators, the most immediate risk comes from plugins and committed themes or from downloading "cracked software" that acts as a distribution vector. Remove outdated plugins, review administrative account permissions and audit files on web servers are essential steps. Activate multifactor authentication in critical accounts, use password managers to avoid reuse and do not trust binaries distributed on video forums or platforms; many campaigns use social engineering in legitimate services to distribute malware. Microsoft and other suppliers often publish indicators and remediation guides after these operations; reviewing their notices helps to prioritize cleaning actions.

At the political and strategic level, the Amadey and StealC coup underlines the need for policies that facilitate cross-border cooperation, intelligence sharing and the ability to intervene in infrastructure in multiple jurisdictions. It also requires rethinking incentives for platforms that allow the monetization of stolen data, and improving the traceability of cryptomonedas to make blockages and confiscations more effective in deterring large-scale operations. The technical and legal community must continue to develop agile procedures to respond to the rapid development of these criminal services; in the meantime, basic defences and digital hygiene remain the first and most effective line of containment.

If you want to deepen the operation and technical implications, I recommend that you review the communiqués of the authorities involved and the technical analysis of the security providers involved in the action, as well as keep their policies and controls up to date: see the general resources published by Europol and public security entrances in Microsoft Security for specific details and recommendations.

Coverage

Related

More news on the same subject.