Microsoft has disrupted more than 200 command-and-control servers and severed criminal control of over 18,000 infected computers as part of a global cybercrime operation that leveraged the Racketeer Influenced and Corrupt Organizations Act to treat multiple malware tools as a single criminal conspiracy. The operation, coordinated with Europol and several private sector partners, recovered approximately 27 million stolen login credentials and identified $47 million worth of crypto assets linked to criminal activity. The action marks one of the most significant private-sector uses of organized crime statutes to dismantle overlapping malware infrastructure at scale.
RICO Statutes Enable Coordinated Action Against Malware Networks
By invoking RICO statutes designed to target organized crime, Microsoft’s legal team established that the tools involved shared overlapping infrastructure, allowing the company to pursue a unified legal strategy against both threats simultaneously. Europol confirmed that 326 servers and 142 domains were actioned by law enforcement and private sector partners, severely disrupting the malware distribution network. “By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cybercriminals, making it harder for attacks to succeed, spread, or recover,” Europol said. This legal approach represents a shift in how technology companies can disrupt cybercrime operations that rely on multiple interconnected malware families.
Operation Endgame Targets SocGholish, Amadey, and StealC Infrastructure
The operation, designated Operation Endgame, disrupted multiple malware loaders including SocGholish, a malware loader linked to the Russian cybercrime group Evil Corp. SocGholish spreads through compromised websites, where visitors are tricked into installing trojanized applications posing as browser extensions or other legitimate software. Europol has responded by cleaning infected WordPress sites and urging administrators to change credentials and tighten security measures. Authorities have also worked to notify parties whose data and credentials were exposed through SocGholish activities. The coordinated takedown simultaneously targeted Amadey and StealC malware, both of which shared infrastructure with SocGholish, preventing the criminal operators from simply shifting resources between tools to maintain their operations.
Countries actively involved in the enforcement action include Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States. Private sector partners supporting the operation include ESET, Proofpoint, IBM X-Force, Bitsight, and Mitsui Bussan Secure Directions, each contributing threat intelligence and infrastructure analysis that enabled the joint action.
What Was the Scope of Operation Endgame?
Operation Endgame represents a coordinated international effort that disrupted over 200 command-and-control servers, severed control of more than 18,000 infected endpoints, recovered 27 million stolen login credentials, and identified $47 million in criminal crypto assets. The operation targeted multiple malware families including SocGholish, Amadey, and StealC through simultaneous legal and law enforcement action, making it one of the largest coordinated disruptions of malware distribution infrastructure in recent years.
What Affected Users Should Do Now
Individuals and organizations potentially impacted by this operation should take immediate steps to secure their digital environments. Change passwords for all online accounts, particularly those that may have been exposed through credential theft. Enable two-factor authentication on every account that supports it to add an additional layer of security against unauthorized access. Monitor financial accounts and credit reports for signs of unusual activity, and consider using a reputable credential monitoring service to detect whether any of your accounts appear in known data breaches. For organizations, deploying a multi-layer endpoint protection solution with real-time threat detection and behavioral analysis capabilities can help identify and block malware infections before they cause damage. Website administrators, particularly those running WordPress, should verify the integrity of their installations, update all plugins and themes to the latest versions, review user accounts for unauthorized access, and scan for any files that may have been injected by compromised sites. Taking these steps now can significantly reduce the risk of falling victim to the same criminal infrastructure should any elements of it become active again.