IC Technology & Surveillance — 2026-06-27

Europol and Microsoft Dismantle Evil Corp-Linked Cybercrime Infrastructure Seizing 326 Servers and $47 Million

BLUFOperation Endgame's infrastructure seizures will likely prove temporary, as Evil Corp's documented reconstitution pattern and Russian state tolerance position SocGholish or Amadey to resume operations within six months.

A two-week Operation Endgame action coordinated by Europol and Eurojust with six national law enforcement agencies and private partners including Microsoft seized 326 servers, 142 domains, and €41 million ($47 million) in cryptocurrency and recovered 27 million stolen login credentials 12. The operation targeted SocGholish, Amadey, and StealC, three cybercrime-as-a-service malware families rented to criminals for ransomware delivery, credential theft, and critical infrastructure attacks 1. Europol linked SocGholish to Evil Corp, the Russian group also associated with Zeus, Dridex, and large-scale ransomware and money-laundering operations 12. Microsoft researchers using AI identified shared infrastructure between Amadey and StealC and reported the pair infected more than 140,000 computers worldwide in the first two weeks of May 2026 alone 23.

Analysis
Evil Corp's documented rebuild cycle, from Zeus to Dridex to successive ransomware variants, makes a likely resumption of SocGholish or Amadey operations within six months of the June seizures. Russian state tolerance eliminates permanent dissolution pressure; the CaaS model further distributes infrastructure costs across jurisdictions beyond coordinated reach. Analytic confidence is moderate, grounded in the historical botnet recovery record rather than direct visibility into reserve infrastructure. Sourcing rests on Europol's own disclosure amplified by secondary outlets without independent corroboration of seizure scale or Evil Corp attribution, constraining operational-scale confidence. Seizure of the shared Amadey-StealC infrastructure raises reconstitution costs enough that a pivot to replacement delivery chains is a genuine competing outcome over the same window. Enterprise detection coverage for SocGholish and Amadey lures should be sustained, not reduced.
4 sources
  1. Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks - Europol
  2. Three cybercrime as a service operations undercut by Microsoft, law enforcement - The Record
  3. Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered - The Hacker News
  4. Amadey, StealC malware operations disrupted in Operation Endgame action - BleepingComputer

View in full brief →

UNCLASSIFIED // OPEN SOURCE