International authorities, in collaboration with private technology companies, have successfully disrupted a cybercrime “assembly line” that enabled criminals to amass millions of login credentials and illicitly obtain over $47 million through ransom payments and other fraudulent activities. This coordinated effort targeted two widely utilized tools in online scams: Amadey and StealC.
Amadey, a malware-as-a-service platform operational since at least 2018, facilitates device compromises and the delivery of malicious payloads for ransomware and other scams. Notably, it was observed last year exploiting GitHub to collect system information from infected devices and install customized payloads. StealC, on the other hand, is an infostealer-as-a-service platform that harvests credentials, authentication cookies, cryptocurrency wallets, browser extensions, and files matching customer-defined patterns.
Although Amadey and StealC operate independently, their widespread use means many cybercriminals employ both tools in their activities. Microsoft’s analysis, utilizing artificial intelligence, revealed that these tools shared underlying infrastructure. This insight enabled Microsoft attorneys to seek a legal order to disrupt both simultaneously, effectively severing a critical link in the cybercrime chain.
This operation is part of a broader trend of international efforts to combat cybercrime. For instance, in February 2024, Operation Cronos led to the disruption of the LockBit ransomware group, described by Europol as a “significant breakthrough in the fight against cybercrime.” The operation resulted in the seizure of LockBit’s technical infrastructure and public-facing leak site on the dark web, marking a substantial blow to the group’s operations.
Similarly, in March 2026, a coordinated international operation supported by Europol targeted Tycoon 2FA, a major phishing-as-a-service platform. This service provided cybercriminals with tools to intercept live authentication sessions and gain unauthorized access to online accounts, including those protected by multi-factor authentication. The operation led to the takedown of 330 domains forming the core infrastructure of Tycoon 2FA, significantly disrupting its operations.
These concerted actions underscore the importance of collaboration between law enforcement agencies and private sector partners in addressing the evolving landscape of cyber threats. By dismantling the infrastructure behind these cybercriminal tools, authorities aim to protect individuals and organizations from the pervasive risks posed by cybercrime.