Europol Freezes €41M in Global Infostealer Crackdown
Europol froze more than €41 million in crypto, took down servers and domains, and recovered almost 27 million stolen credentials in a two-week global operation targeting three infostealers.
Europol announced it froze over €41 million in criminal cryptocurrency and dismantled servers and domains linked to three infostealer families during a two-week global operation called Operation Endgame. Authorities removed command-and-control infrastructure, recovered almost 27 million stolen credentials and cleaned nearly 15,000 infected websites used to harvest account data and drain crypto wallets.
The operation targeted SocGholish, Amadey and StealC. SocGholish infects visitors to compromised websites with fake browser-update prompts. Amadey gains initial access and drops further payloads. StealC, marketed as an infostealer service since 2023, scrapes passwords, browser cookies and crypto wallet data from infected machines. Researchers reported StealC’s control panel included a plugin designed to try to decrypt MetaMask seed phrases.
Authorities said the crackdown removed 326 servers and seized 142 domains. Law enforcement recovered credentials from more than 385,000 compromised systems. Microsoft, a partner in the action, tied Amadey and StealC to over 140,000 infected computers worldwide in the first two weeks of May. Earlier phases of Operation Endgame had turned up login data linked to more than 100,000 crypto wallets that had not been emptied.
Microsoft’s Digital Crimes Unit filed a U.S. racketeering lawsuit that treated two malware families as part of a single criminal conspiracy. Using AI-assisted analysis tools, investigators identified shared infrastructure between Amadey and StealC, disrupted more than 200 command-and-control servers and located over 18,000 victim computers that have begun to be cut off from attacker control.
Investigators described infostealers as a primary route for stealing crypto by quietly copying wallet files, private keys and seed phrases from users’ devices. The malware reaches victims through a range of lures, including fake AI tools, altered game assets and pirated software, then exfiltrates credentials that allow attackers to take over accounts or transfer funds.
Authorities warned takedowns do not eliminate malware permanently and noted operators often release updated builds; security teams reported a new StealC build this month. Europol and partners are routing victim alerts through services that let people check whether their credentials or wallet keys have been exposed so affected users can take steps to secure accounts.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








