Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
International Operation Disrupts Two Major Cybercrime Platforms, Seizes $47 Million in Crypto Assets

What Happened
International law enforcement and a coalition of private technology companies announced this week they had disrupted two widely used cybercrime platforms in a single coordinated strike. The operation, called Operation Endgame, targeted Amadey and StealC — two distinct malware-as-a-service tools that, taken together, formed what Microsoft described Wednesday as a cybercrime "assembly line."
Amadey has been circulating since at least 2018. It is a malware-as-a-service platform used to compromise devices and deliver ransomware payloads. StealC is an infostealer that harvests login credentials, authentication cookies, cryptocurrency wallets, browser extensions, and files matching patterns defined by whoever rented the service. Neither tool is new, and neither was built by the same people.
The RICO Angle
What made this operation legally distinctive was how Microsoft's attorneys framed it. According to Microsoft, AI analysis of both platforms revealed they shared underlying infrastructure, even though they operate independently. That overlap gave attorneys grounds to invoke RICO statutes, the same organized-crime framework used against drug trafficking networks and the mob.
With RICO on the table, lawyers could treat Amadey and StealC as components of a single criminal conspiracy rather than two separate cases. That mattered for the scope of the court order Microsoft obtained, which authorized disruption of more than 200 command-and-control servers and severed criminal access to more than 18,000 infected computers, according to Microsoft.
The Numbers from Europol
Europol, which coordinated the law-enforcement side of the operation, reported broader infrastructure impact: 326 servers and 142 domains taken down in total. Europol said authorities recovered as many as 27 million stolen login credentials and uncovered $47 million worth of crypto assets of criminal origin.
"By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cybercriminals, making it harder for attacks to succeed, spread, or recover," Europol said.
Additional private-sector partners included ESET, Proofpoint, IBM X-Force, Bitsight, and Mitsui Bussan Secure Directions, according to Ars Technica's reporting on the operation.
Europol also noted that a third tool, SocGholish — a malware loader — was disrupted as part of Operation Endgame, though the source material on that element was incomplete.
What This Actually Accomplished
Taking down infrastructure is not the same as arresting the people who built or rented these platforms. No arrests have been publicly announced in connection with Operation Endgame as of June 25, 2026. The servers are down; the operators are not necessarily in custody.
Cybercrime infrastructure gets rebuilt. The groups behind Amadey and StealC can, in principle, spin up new servers. The 27 million recovered credentials represent victims whose data was already stolen. Most of those people may never know their information was compromised in the first place.
The Strongest Counter-Argument
Skeptics of these types of operations — and there are legitimate ones — point out that takedowns often function more as press events than permanent disruptions. Researchers at multiple security firms have documented cases where botnet infrastructure comes back online within weeks of a high-profile seizure. If no one is prosecuted and convicted, the operators absorb the loss of a few servers and move on.
Microsoft has an obvious interest in publicizing its role in law-enforcement actions; it is good for its security business reputation. That should be weighed alongside Europol's independent reporting.
The RICO approach is genuinely novel in this context, though, and if it holds up legally, it creates a precedent for treating loosely connected cybercrime toolsets as single conspiracies. That could meaningfully expand the scope of future court orders.
What Comes Next
The concrete open question is prosecution. Europol's involvement means there are at least some law-enforcement leads being pursued across member states. But infrastructure seizure and criminal charges are two very different outcomes, and as of today no charges have been publicly announced. Whether the $47 million in identified crypto assets gets formally forfeited, and to whom any recovered funds would go, has not been resolved.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.