Europol Seizes $47M in Crypto, Disables 326 Malware Servers
Europol seized $47 million in cryptocurrency, disabled 326 servers and 142 domains, and recovered 27 million credentials in Operation Endgame targeting three malware platforms.
On June 27, 2026, Europol led Operation Endgame, an international action that seized $47 million in cryptocurrency, disabled 326 servers and took down 142 domains. The operation recovered more than 27 million leaked credentials and targeted the back-end infrastructure that supported the SocGholish, Amadey and StealC malware platforms. Agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom and the United States participated, with technical support from Microsoft and Coinbase.
The seized servers and domains hosted control panels, distribution channels and data exfiltration points used to operate and scale “cybercrime-as-a-service” offerings. Investigators targeted the supporting infrastructure rather than individual malware samples to interrupt the services criminals used to rent or resell access and tools.
SocGholish was delivered through compromised WordPress sites as fake browser updates and was used to stage ransomware. StealC harvested passwords and identity data from infected machines and made that information available to buyers. Amadey spread through phishing campaigns, delivered additional payloads and collected sensitive data. Microsoft tracked roughly 140,000 infections linked to Amadey and StealC during the first two weeks of May, and investigators found just under 15,000 sites hosting SocGholish components.
Beyond the crypto seizure and credential recoveries, the data will be used in follow-up probes to identify victims and disrupt marketplaces where stolen information is traded. National police units in Latvia, Lithuania, Portugal, Poland and Spain executed local seizures and domain takedowns. Private companies provided technical analysis, threat-hunting support and assistance tracing and freezing cryptocurrency flows identified as of criminal origin.
Europol described the goal: “Instead of focusing solely on individual threats, Europol, law enforcement and judicial authorities, as well as private industry partners, disrupted the entire chain that allows cyberattacks to scale.” Operation Endgame follows earlier takedowns of infrastructure used to bypass multi-factor authentication, including platforms such as Tycoon 2FA.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








