Targeting Cybercrime ‘Assembly Lines:’ Europol Announces Malware Crackdown
As part of the takedown, SocGholish infrastructure tied to fake browser-update scams was heavily impacted, including remediation of nearly 15,000 compromised WordPress sites.

As part of the takedown, SocGholish infrastructure tied to fake browser-update scams was heavily impacted, including remediation of nearly 15,000 compromised WordPress sites.
June 25, 2026 | 2 min read

Law enforcement agencies from a number of different countries have banded together to take down several malware variants, including SocGholish, StealC, and Amadey.
In a Wednesday announcement, Europol said they worked with law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the UK, the U.S, and several private partners to carry out the disruption over the last two weeks.
The main common goal behind this disruption was to interrupt the "assembly lines" cybercriminals are using to launch ransomware, financial fraud, and attacks on critical infrastructure, said Europol. As SocGholish, StealC, and Amadey are typically used as droppers or loaders during attacks, they are used to establish access as part of a link in a larger attack chain.
“The neutralised malware variants were offered as a service (‘cybercrime-as-a-service’), with other cybercriminals using them as a tool for the initial infection of targeted systems,” according to Europol in a Wednesday press release. “They subsequently served as a starting point for further criminal activities, such as installing ransomware for digital extortion or fraudulent use of data.”
As part of the operation (part of a larger international ongoing initiative called Operation Endgame) the agencies targeted 326 servers and 142 domains, seized more than €41 million in criminal cryptocurrency, and recovered 27 million stolen credentials.
The malware variants in question have been around for years. SocGholish (a dropper/loader) has typically been spread in a fairly specific manner: threat actors would compromise vulnerable WordPress websites, and then use those compromised websites to distribute fake browser updates to victims. Victims would attempt to install the updates and inadvertently install the malware.
As part of the takedown, SocGholish infrastructure tied to fake browser-update scams was heavily impacted, including remediation of nearly 15,000 compromised WordPress sites.
The disruption cracked down on StealC (an infostealer with dropper functionalities), which was developed primarily to target passwords and stored access data. Amadey (a dropper/loader with stealer functionalities mainly spread through phishing) was also impacted. Both of these have typically been dropped at the beginning of attacks, post-compromise, to set the stage for threat actors to launch further attacks.
This takedown highlights a growing focus by law enforcement agencies on dismantling the cybercrime “supply chain,” targeting malware loaders and infostealers before they can enable ransomware, fraud, and broader intrusions. Previously, the FBI and Europol targeted loaders like Bumblebee (in 2024), as well as others in the dropper/loader ecosystem like IcedID, Pikabot, and Smokeloader.
Other recent takedowns have included targeting VPN services, bulletproof hosting providers, residential proxy networks, and more.
"This operation marked a shift in strategy: instead of focusing solely on individual threats, Europol, law enforcement and judicial authorities, as well as private industry partners disrupted the entire chain that allows cyberattacks to scale," according to Europol. "Amadey and StealC, two widely used malware tools, were targeted by Microsoft in tandem due to their interconnected roles."
June 25, 2026 | 2 min read
Lindsey O’Donnell-Welch is an award-winning journalist who strives to shed light on how security issues impact not only businesses and defenders on the front line, but also the daily lives of consumers.