Europol Smashes Amadey and StealC Malware Networks — 27 Million Credentials Seized
In a two-week operation, Europol and law enforcement from the Netherlands, Canada, Germany, and the United States have dismantled the criminal infrastructure behind two of the internet's most active malware tools, according to The Hacker News.
Amadey and StealC were both sold as malware-as-a-service (MaaS) — a subscription-based criminal model where anyone can rent ready-made hacking tools, the same way a business might rent software. Amadey worked as a loader, quietly installing additional malicious software onto victims' machines. StealC was the harvester: once inside, it grabbed passwords, browser cookies, credit card numbers, and session data.
Authorities tore down 326 servers and 142 domains. They also identified and froze over $47 million in cryptocurrency tied to criminal activity, and recovered 27 million stolen login credentials — credentials that could have been used for fraud, ransomware, or selling on dark web markets.
The timing is notable. Days before this operation concluded, a separate action cleaned up nearly 15,000 compromised WordPress websites that were being used to spread another loader called SocGholish.
If your email address appears in any data breach notification over the coming weeks, take it seriously — these recovered credentials may surface through services like Have I Been Pwned.
What to do: Visit haveibeenpwned.com today, enter your email address, and check whether your credentials have been caught up in any known breach. If they have, change those passwords immediately and turn on two-factor authentication where possible.
Sources

