Europol, Bitdefender, ESET, and Microsoft Takedown Amadey and StealC Ransomware Infrastructure
Update threat intelligence feeds to remove Amadey and StealC infrastructure after the Europol takedown.
Update threat intelligence feeds to remove Amadey and StealC infrastructure and monitor for residual indicators.
Summary
Europol announced a coordinated law‑enforcement operation that dismantled the criminal infrastructure behind the Amadey and StealC ransomware groups. The operation involved private sector partners Bitdefender, Bitsight, ESET, and Microsoft, and targeted the 'assembly lines' used by cybercriminals to launch ransomware, financial fraud, and attacks on critical infrastructure. The takedown disrupted the command‑and‑control servers and payment channels that enable these groups to operate at scale. Europol emphasized that the action was part of a broader effort to protect vulnerable organizations worldwide.
Amadey and StealC had been responsible for a series of high‑profile ransomware campaigns, leveraging stolen credentials and exploiting software vulnerabilities. The removal of their infrastructure reduces the threat landscape for enterprises and reduces the risk of future attacks. Security teams should update threat intelligence feeds to reflect the loss of these command‑and‑control nodes. Continued monitoring of related indicators of compromise remains essential to detect any residual activity.
Key changes
- Europol coordinated a takedown of Amadey and StealC ransomware infrastructure
- Private sector partners Bitdefender, Bitsight, ESET, and Microsoft participated in the operation
- The operation targeted the 'assembly lines' used for ransomware, financial fraud, and critical infrastructure attacks
- Command‑and‑control servers and payment channels for Amadey and StealC were disabled
- The takedown reduces the threat landscape for enterprises and lowers ransomware risk
- Security teams should update threat intelligence feeds and continue monitoring related indicators