ESET, a global leader in cybersecurity, helped halt the activities of the Amadey botnet and the Stealc information stealer by providing technical analysis, infrastructure tracking, and affiliate-level insights.
ESET telemetry data indicates that Amadey is active globally, without focusing on any specific region. The highest detection rates were observed in India, Turkey, Egypt, Mexico, and Spain. Similarly, Stealc spreads globally without a specific regional focus, with the highest detection rates recorded in the USA, Poland, and Italy.
ESET Research assisted in disrupting the operations of the Amadey botnet and the Stealc information stealer by providing technical analysis, infrastructure tracking, and affiliate-level insights. Both operate as “Malware-as-a-Service” (MaaS) offerings. Coordinated by Microsoft’s Digital Crimes Unit (DCU), BitSight, Lumen, and Mitsui Bussan Secure Directions (MBSD), the operation aimed to cripple cybercriminal activities by targeting the entire known network infrastructure used by Amadey and Stealc affiliates. Concurrently, Stealc was being investigated under “Operation Endgame”—a joint effort involving IBM, Proofpoint, and European law enforcement partners, including Europol’s European Cybercrime Centre (EC3), the German Federal Criminal Police Office, and the national police forces of the Netherlands and Denmark. ESET contributed to the success of this operation by sharing threat intelligence—including technical analyses, statistical data, known command-and-control (C&C) servers, encryption keys, campaign and compilation identifiers—gathered during its long-term monitoring of both malware families.
ESET researcher Jakub Tomanek, who supported efforts to disrupt Amadey and Stealc, stated: “ESET has been tracking both the Amadey botnet and the Stealc info-stealer for the past three years. As part of the disruption operation, we shared technical indicators and configuration data derived from analyzed malware samples, alongside statistics covering the period from Q4 2025 through the first half of 2026. Our automated systems analyze Amadey and Stealc samples in detail and identify key areas for large-scale monitoring. These include C&C servers, compilation identifiers, encryption keys, URL paths, campaign identifiers, and other embedded values used by the malware families to communicate with attacker-controlled infrastructure.”
Sharing technical analyses, statistical data, and threat intelligence—such as C&C server lists, affiliate identifiers, and encryption keys—enables law enforcement agencies to identify, prioritize, and take action against these infrastructures with a high degree of confidence.
Amadey is a modular malware loader; while its primary purpose is to deploy additional malware onto compromised systems, it also offers modules for data exfiltration and remote access. In contrast, Stealc is a typical “info-stealer-as-a-service.” It targets credentials, cookies, cryptocurrency wallets, browser extensions, and files matching patterns defined by its affiliates.
Both malware families are sold as a service and promoted on darknet forums. In both ecosystems, affiliates receive a self-hosted management panel that must be deployed on their own server infrastructure. This requires a certain level of technical skill from the affiliates and grants them direct control over victim data and payload distribution.
While distribution methods ultimately depend on the individual affiliate, ESET telemetry data has consistently shown that both malware families spread through a wide variety of channels. The most common methods include fake software updates, installers for cracked software, and third-party malware installers.
Amadey employs a pay-per-rebuild model. After purchasing a license, affiliates pay an additional fee each time they need to generate a new build (for example, when switching to a new C&C server). In other words, Amadey operators did not provide a build tool to their affiliates; instead, samples were compiled on demand for each affiliate. The service offers three modules for further data exfiltration and access: a clipboard monitoring module, a credential-stealing module, and a VNC-based remote access module. The price of the service is 600 USD (payable in Bitcoin) for a single license, with an additional fee of 50 USD charged for each rebuild.
Stealc, on the other hand, has adopted a more partner-friendly approach, offering unlimited build generation as part of its subscription. This reduces the operational cost of modifying the C&C infrastructure and makes it easier for partners to generate new samples whenever needed. It targets a wide range of data sources, including credentials stored by web browsers, email clients, FTP clients, gaming platforms, cryptocurrency wallet files, and browser extensions. Stealc is sold via monthly subscription, with the lowest-priced option costing $1,000 USD for six months.
Seeking to avoid impersonation scams, both operators explicitly instructed potential partners on darknet forums to contact them only through official channels. While Amadey directed buyers to private messages on the darknet forum where the product was advertised, Stealc utilized either private messages on darknet forums or Telegram.
ESET will continue to monitor the activities of both families and track any attempts to re-establish operational infrastructure following the disruption of their operations.