ESET Helps Takedown Amadey Botnet and Stealc in Operation Endgame
Because both malware families are sold as services with affiliates running their own infrastructure, the takedown depended on ESET's clustering analysis to identify shared C&C servers worth prioritizing.
Reporting from 1 source: ASCII.jp.
ESET joined Operation Endgame, a global takedown of the Amadey botnet and the Stealc info-stealer. The operation neutralized about 50 domains and 200 IP-based C&C servers. ESET contributed three years of tracking data, technical analysis, and threat intelligence. Both malware families are sold as services, with affiliates hosting their own infrastructure, which made clustering analysis essential to the targeting.
Both malware families are advertised on darknet forums, and ESET used the threat intelligence platform Flare.io to monitor those communities. The business models differ. Amadey charges affiliates per build generation, while Stealc sells a subscription with unlimited builds. Because affiliates host their own admin panels on their own servers, the operation could not cut a single central command point. ESET grouped samples by C&C servers, build identifiers, encryption keys, and campaign identifiers to find shared infrastructure worth prioritizing. Distribution runs through fake software updates, cracked installers, and third-party loaders.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.