Podcast Episode
Microsoft's Digital Crimes Unit used Copilot to analyse the malware's complex code by asking questions in plain English, surfacing hidden data and testing findings in minutes rather than the hours or days manual analysis would normally take. The company described it as a novel use of AI in a disruption operation.
Microsoft Uses Copilot AI to Help Dismantle Amadey and StealC Malware Networks in Global Takedown
June 26, 2026
0:00
6:07
Microsoft's Digital Crimes Unit used its Copilot AI assistant to help investigators analyse and link the Amadey and StealC malware families, enabling a sweeping international takedown. Under Europol's Operation Endgame, authorities seized 326 servers, took down 142 domains, and froze over 41 million euros (around $47 million) in criminal cryptocurrency. The two tools had been tied to more than 140,000 infected computers in just the first two weeks of May 2026.
AI Joins the Fight Against Cybercrime
Microsoft has confirmed that its Copilot AI assistant played a central role in a major international operation to dismantle two of the world's most widely used cybercrime tools, Amadey and StealC. Announced on 24 June 2026, the action was carried out under Operation Endgame, a multinational effort coordinated by Europol and involving law enforcement from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States.Microsoft's Digital Crimes Unit used Copilot to analyse the malware's complex code by asking questions in plain English, surfacing hidden data and testing findings in minutes rather than the hours or days manual analysis would normally take. The company described it as a novel use of AI in a disruption operation.
How Amadey and StealC Worked Together
Amadey is a dropper and loader, typically spread through phishing campaigns, that gains initial access to victim devices. StealC is an infostealer that extracts passwords and sensitive data from compromised systems. Together they formed an efficient cybercrime assembly line. In just the first two weeks of May 2026, Microsoft's telemetry linked the pair to more than 140,000 infected computers worldwide, and the company has since severed criminal control of over 18,000 victim machines.A Legal Breakthrough Powered by AI
Though Amadey and StealC were built by separate criminals, AI-assisted analysis revealed they shared the same underlying infrastructure. That insight let Microsoft treat both as a single conspiracy under the Racketeer Influenced and Corrupt Organizations Act (RICO), the same legal strategy the company first used against the Zeus botnets in 2012 and later against threats including Trickbot and RaccoonO365.The Scale of the Takedown
Across all targeted malware families, which also included the SocGholish dropper, authorities took down 326 servers and seized 142 domains, while identifying and restricting cryptocurrency assets valued at over 41 million euros (about $47 million). Around 27 million stolen login credentials were recovered, and nearly 15,000 infected WordPress websites were cleaned of SocGholish infections.A Shift in Strategy
Europol framed the operation as targeting the entire criminal supply chain rather than individual threats. The neutralised tools operated under a "cybercrime-as-a-service" model, rented out to other criminals to gain access before deploying ransomware or committing fraud. Private sector partners including Proofpoint, IBM X-Force, Bitdefender, and the Shadowserver Foundation supported the effort, with researchers even exploiting a flaw in StealC's own control panel during the disruption.Published June 26, 2026 at 8:50am