$47M in Crypto Frozen in Global Infostealer Takedown: Europol

by shayaan

In short

  • A global law enforcement operation has frozen more than €41 million worth of criminal cryptocurrency as part of Operation Endgame, Europol said on Wednesday.
  • The strike dismantled the infrastructure behind three malware families, SocGholish, Amadey and StealC, which steal passwords and crypto wallet data to fuel fraud and ransomware.
  • Police took 326 servers and 142 domains offline and recovered approximately 27 million stolen login details from more than 385,000 infected systems.

A global crackdown on cybercrime-as-a-service malware that is quietly draining crypto wallets has frozen tens of millions of dollars in stolen funds.

Law enforcement identified, flagged and froze more than €41 million (approximately $47 million) in criminal crypto assets in the final phase of Operation Endgame, Europol said on Wednesday. The two-week multi-country strike dismantled the infrastructure behind three malware families: SocGholish, Amadey, and StealC.

All three target crypto users. StealC, an infostealer sold as a service since 2023, scrapes passwords, browser cookies, and crypto wallet data from infected machines. The control panel even contained a plug-in that attempted to decrypt victims’ basic sentences. Metamask wallets, researchers at Evidence point found.

Amadey gains the first foothold and drops even more malware, while SocGholish, linked to Russian group Evil Corp, infects people through fake browser update prompts on hacked websites. Together they form the front end of attacks that end in empty wallets, account takeovers and ransomware.

Police took down 326 servers and 142 domains, recovered nearly 27 million stolen credentials from more than 385,000 compromised systems, and cleaned up nearly 15,000 infected websites, many of them small businesses. Microsoft, a partner in the operation, linked Amadey and StealC to more than 140,000 infected computers worldwide in the first two weeks of May alone.

See also  Swiss Crypto Firm SCRYPT Puts Treasury on Franklin Templeton's Tokenized Money Market Fund

What are info stealers?

Infostealers have become a major route to stolen cryptocurrencies, which are being quietly shut down wallet files, private keysAnd seed sentences of victims’ devices. They use a variety of vectors to target crypto users, including fake AI tools, Steam wallpapers, and pirated game mods.

The scale of exposure is enormous. A previous Operation Endgame action At the end of last year, login details of more than 100,000 crypto wallets were exposed, stolen from victims but not yet emptied.

Microsoft’s Digital Crimes Unit separately submitted an American racketeering case in which two malware families were treated as one criminal conspiracy for the first time. Using AI tools, including Copilot, to analyze the malware, researchers found that Amadey and StealC, although built by different criminals, ran on shared infrastructure, allowing Microsoft to charge for both activities under the RICO Act and disrupt more than 200 command-and-control servers. Since then, it has identified more than 18,000 victim computers and has begun to break the attackers’ control.

Such removals rarely kill malware completely, and operators tend to regroup with StealC dispatch a new build as recent as this month. For the time being, Europol and its partners are forwarding victim alerts through services such as Am I pwned?so users can check if their login details and wallet keys are already in criminal hands.



Source link

You may also like

Latest News

Copyright © Sovereign Wealth Signals