ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET, in collaboration with Microsoft DCU and other partners, successfully disrupted the Amadey and Stealc botnets as part of Operation Endgame. These botnets, sold as a service on darknet forums, utilize a MaaS model where affiliates deploy and manage their own infrastructure. ESET’s research focused on clustering Amadey and Stealc activity, leveraging technical indicators like C&C server URLs, RC4 keys, and the ‘sd’ value to identify and target critical infrastructure. The disruption targeted around 50 domains and nearly 200 active C&C servers, highlighting the effectiveness of a clustering approach in combating MaaS malware ecosystems. Amadey, a modular malware loader, has been a persistent threat for years, with ongoing updates and a pay-per-rebuild model, while Stealc offers unlimited build generation. The operation demonstrated the importance of understanding the business model of MaaS malware to effectively target and dismantle these operations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data