Between 15 and 19 June 2026, Europol and agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom and the United States disrupted infrastructure behind three malware families — Amadey, StealC and SocGholish — as the latest phase of Operation Endgame.
The published totals: 326 servers and 142 domains taken down, more than $46 million in cryptocurrency identified and frozen, and approximately 27 million stolen credentials recovered from over 385,000 compromised systems.
The Recovered Credentials Are The Useful Output
Server seizure figures are the headline and the least durable result. Infrastructure is rented, and rebuilding it is a procurement exercise measured in days.
Twenty-seven million credentials recovered from 385,000 systems is different in kind. Those are specific accounts belonging to specific people and organisations, and once in the hands of agencies and notification services they can be pushed into password-reset workflows and breach-notification feeds. That effect does not depend on the operators staying offline.
Loaders Are The Layer Worth Disrupting
None of the three families named is ransomware. Amadey and StealC are loaders and stealers; SocGholish is a delivery framework. They sit upstream of ransomware in the access market — establishing the foothold and harvesting the credentials that ransomware affiliates later buy.
That targeting is deliberate and, we think, correct. Ransomware brands are numerous, rebrand frequently and are difficult to attribute to individuals. The access layer underneath them is more concentrated, more commercial and more traceable — because somebody has to be paid.
The measure worth watching over the next two quarters is not whether these families return. It is whether the price of initial access moves.
Compiled from published law-enforcement announcements and reporting, listed below. Seizure and recovery figures are as published by the agencies involved. Corrections: corrections@forensicpost.com.