One-two punch delivered in global operation disrupts cybercrime "assembly line"
"Operation Endgame" simultaneously disrupts two widely used crime tools.
Signal weather
Rising
Momentum is building quickly, so this card is a good early entry point into the topic.
International authorities and a raft of private technology companies say they have disrupted a cybercrime “assembly line” that allowed crooks to collect millions of login credentials and steal more than $47 million in ransom payments and by other fraudulent means. The crux of the operation was the simultaneous targeting of two unrelated tools that are widely used in various online scams. The first is Amadey, a malware-as-a-service platform for compromising devices and delivering malicious payloads for ransomware and other scams. Amadey has been observed in the wild since at least 2018 and was seen last year abusing GitHub as it collected system information from infected devices and installed customized payloads. The second tool was StealC, an infostealer-as-a-service platform that collects credentials, authentication cookies, cryptocurrency wallets, browser extensions, and files whose names match customer-defined patterns. Severing a critical link in the cybercrime chain Amadey and StealC are separate tools that are run independently of each other. Given their widespread use, however, many customers use both in their individual cybercrime activities. The tools also, it turns out, relied on some of the same underlying infrastructure to run. Microsoft said it made this determination after analyzing the tools using AI. This insight allowed Microsoft attorneys to seek an order disrupting both at the same time. Read full article Comments
Stay on the signal
Follow One-two punch delivered in global operation disrupts cybercrime "assembly line"
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Entity pages
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
1
Related articles
More stories that share tags, source, or category context.
Underpromise, overdeliver? Hands-on with the $24,950 Slate auto.
It has 205 miles of bare-bones range.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Experimental wine bottle tracks oxygen moving through the cork
The small bit of air in the bottle sees oxygen and other chemicals move in and out.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
FCC plans ID mandate that could block anonymous use of prepaid burner phones
Privacy advocates and domestic violence groups say ID mandate is a big mistake.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Formula E reveals first calendar for GEN4 with lots of real race tracks
Brands Hatch, COTA, and Zandvoort will all hold an e-Prix in 2027.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Underpromise, overdeliver? Hands-on with the $24,950 Slate auto.
It has 205 miles of bare-bones range.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Disney agreed to $50M settlement over claims it made live-TV streaming expensive
Lawsuit alleged Disney inflated market prices by making carriers include ESPN.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Experimental wine bottle tracks oxygen moving through the cork
The small bit of air in the bottle sees oxygen and other chemicals move in and out.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
FCC plans ID mandate that could block anonymous use of prepaid burner phones
Privacy advocates and domestic violence groups say ID mandate is a big mistake.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.