Microsoft Helps Law Enforcement Dismantle Malware Infrastructure After 140,000 Computers Infected in Two Weeks
SocGholish, Amadey and StealC are tools used to distribute malware and steal login credentials and financial data. They rely on command-and-control (C2) servers for instructions. When criminal groups share infrastructure, access to compromised computers can be resold, so taking servers offline can disrupt multiple attack chains at once.
Europol recently joined forces with Microsoft and other organizations to target the criminal networks behind the three malware strains. Microsoft used AI to accelerate its analysis and determined that two separate hacker groups were sharing the same infrastructure. The law-enforcement operation has disrupted more than 200 C2 servers, while Amadey and StealC infected more than 140,000 computers in two weeks.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.