Europol Freezes Over €41 Million in Crime-Linked Crypto and Disrupts Three Malware Networks

Europol Freezes Over €41 Million in Crime-Linked Crypto and Disrupts Three Malware Networks

N
News Editor 01
2026-07-22 21:45:14
Europol said Operation Endgame’s latest phase froze more than €41 million in criminal crypto assets and dismantled infrastructure tied to SocGholish, Amadey, and StealC.
Europolcrypto securitymalwareinfostealerOperation Endgame

Europol said the latest phase of Operation Endgame identified, flagged, and froze more than €41 million in criminally sourced crypto assets. The action also targeted the infrastructure behind SocGholish, Amadey, and StealC, three malware families linked to password theft, crypto wallet data theft, fraud, account takeovers, and ransomware activity.

Authorities mapped the malware chain behind wallet theft

According to Europol, Amadey was used to gain initial access to victim systems and make way for additional malware. SocGholish, which authorities linked to the Russian cybercrime group Evil Corp, spread through fake browser update alerts placed on compromised websites. Investigators said these tools often sat at the start of an attack chain that could end with drained wallets or ransomware deployment.

The report described infostealers as malware built to quietly collect saved passwords, wallet files, private keys, and recovery phrases from infected devices. For crypto users, that creates a direct route to theft. Attackers do not need to break a blockchain if they can extract the credentials that control a wallet.

326 servers and 142 domains were taken offline

Law enforcement agencies deactivated 326 servers and 142 domain names during the operation. They also recovered about 27 million stolen credentials tied to more than 385,000 compromised systems. Nearly 15,000 infected websites, mostly small business sites, were cleaned up as part of the same effort.

Microsoft, which supported the operation, said that in just the first two weeks of May it found more than 140,000 computers infected with Amadey and StealC. The company’s Digital Crimes Unit added that over the past nine months, five separate organizations operating under the Cybercrime-as-a-Service model had been dismantled.

Crypto wallet data remained a primary target

The article said infostealer malware has become one of the main methods used in crypto theft. Distribution methods went beyond standard phishing. Criminal operators also used fake AI tools, gaming platform themes, and pirated game plugins to spread malware. Microsoft said Amadey and StealC were built by different groups but relied on shared infrastructure, allowing both to be targeted within a single criminal network.

An earlier phase of Operation Endgame had already shown that login credentials for more than 100,000 crypto wallets had been compromised, though not yet exploited at that point. In the latest phase, authorities said they were still working to cut off attacker control and had identified more than 18,000 victim computers so far.

Officials warned the threat can quickly return

Authorities said operations like this can seriously disrupt malware networks, but removing malicious software completely remains difficult because operators often regroup and adapt. The report also noted that a new version of StealC appeared this month.

Europol and its partners directed potential victims to services such as Have I Been Pwned so they can check whether login credentials or crypto wallet data may have been exposed and take protective action.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.