<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/microsoft-s-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure-zuasbjopz" -->

---
title: Microsoft’s ‘New Approach’ to Fighting Malware Nabs...
description: Microsoft, Europol, law enforcement from six countries, and 10 cybersecurity firms dismantled the shared infrastructure behind two widely used infostealer...
canonical: https://daily.dev/posts/microsoft-s-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure-zuasbjopz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Microsoft’s ‘New Approach’ to Fighting Malware Nabs Amadey, StealC Infrastructure | daily.dev
og:description: Microsoft, Europol, law enforcement from six countries, and 10 cybersecurity firms dismantled the shared infrastructure behind two widely used infostealer...
og:url: https://daily.dev/posts/microsoft-s-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure-zuasbjopz
og:image: https://api.daily.dev/og/posts/ZuASBJoPZ.png
og:image:alt: Microsoft’s ‘New Approach’ to Fighting Malware Nabs Amadey, StealC Infrastructure
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft’s ‘New Approach’ to Fighting Malware Nabs Amadey, StealC Infrastructure

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 5 min read · 0 upvotes · 0 comments

## Summary

Microsoft, Europol, law enforcement from six countries, and 10 cybersecurity firms dismantled the shared infrastructure behind two widely used infostealer malware families — Amadey and StealC — as part of Operation Endgame. A key innovation was using Microsoft Copilot AI to analyze malware binaries, decrypt strings, identify hardcoded C2 servers, and establish legal connections between the two operations under RICO law. The operation took down more than 200 C2 servers, identified 18,000+ victim computers, and seized systems linked to over 25.6 million stolen credentials from 385,000 compromised machines. By treating both malware families as part of a single criminal conspiracy rather than separate operations, investigators were able to disrupt the broader cybercrime assembly line more effectively.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/06/microsofts-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure>

## Similar posts on daily.dev

- [Amadey, StealC malware operations disrupted in Operation Endgame action](https://daily.dev/posts/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action-rivgi9vxr) · BleepingComputer · 0 upvotes · 0 comments
- [One-two punch delivered in global operation disrupts cybercrime “assembly line”](https://daily.dev/posts/one-two-punch-delivered-in-global-operation-disrupts-cybercrime-assembly-line--1qfr3yczv) · Ars Technica · 0 upvotes · 0 comments
- [Microsoft uses AI to link two malware operations in racketeering suit](https://daily.dev/posts/microsoft-uses-ai-to-link-two-malware-operations-in-racketeering-suit-mkv2bvre8) · The Register · 0 upvotes · 0 comments
- [Microsoft warns of surge in ACR Stealer attacks on customers](https://daily.dev/posts/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers-mtjfp3laf) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#microsoft](https://daily.dev/tags/microsoft), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/microsoft-s-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure-zuasbjopz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Microsoft’s ‘New Approach’ to Fighting Malware Nabs Amadey, StealC Infrastructure","url":"https://daily.dev/posts/microsoft-s-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure-zuasbjopz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/microsoft-s-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure-zuasbjopz"},"datePublished":"2026-06-25T20:11:51.440Z","dateModified":"2026-06-25T21:07:43.947Z","description":"Microsoft, Europol, law enforcement from six countries, and 10 cybersecurity firms dismantled the shared infrastructure behind two widely used infostealer...","image":"https://media.daily.dev/image/upload/s--foaA6JGU--/f_auto/v1722860399/public/Placeholder%2004","thumbnailUrl":"https://media.daily.dev/image/upload/s--foaA6JGU--/f_auto/v1722860399/public/Placeholder%2004","isAccessibleForFree":true,"articleSection":"Security Boulevard","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Security Boulevard","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/3613c832180040de8d85bb29f74395be","url":"https://daily.dev/sources/securityboulevard"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/microsoft-s-new-approach-to-fighting-malware-nabs-amadey-stealc-infrastructure-zuasbjopz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"microsoft,malware","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Boulevard","item":"https://daily.dev/sources/securityboulevard"},{"@type":"ListItem","position":3,"name":"Microsoft’s ‘New Approach’ to Fighting Malware Nabs Amadey, StealC Infrastructure"}]}
```

