On June 25, Europol indicated that the latest round of transnational law enforcement “Final Action” had frozen more than Euro41 million and approximately $47 million worth of encrypted assets involved. The operation focused on a network of malicious software that specifically stole passwords, browsers, cookies and encrypted wallet data.
Three types of malware are locked.
According to law enforcement agencies, part of the infrastructure behind SocGholish, Amadey and SteelC was dismantled during the current round. These three types of malware are often used in follow-up fraud, account take-over and extortion software attacks, of which StealC has been available on a “i.e. service” basis since 2023.
Researchers have previously found that StealC not only captures passwords and wallet data from victim equipment, but also has a control panel with decryption plugins for MetaMask aids. Amadey was usually responsible for the initial invasion and placed more malicious programs; SocGholish was often disseminated through a false browser that was accessed.
326 servers seized
Europol stated that during the operation 326 servers, 142 domain names were seized and some 27 million stolen vouchers were recovered from more than 385 thousand infected equipment. At the same time, nearly 15,000 sites, many of which were small and medium-sized enterprises, had been cleaned up.
Microsoft, as one of the participants, indicated that only two weeks before May, Amadey and StealC were associated with over 140,000 infected computers worldwide. The Microsoft Digital Crime Department has also initiated a lawsuit in the United States based on the Anti-Fraud and Corruption Organization Act, which seeks to treat two types of malicious software as the same criminal collaboration network.
Encrypt Wallet as Main Target
Theft software has become an important entry point for the theft of encrypted assets, often targeting wallet documents, private keys and assistive notes. The attackers used to induce users to download files disguised as AI tools, Steam wallpapers or pirated game modules.
Europol mentioned that in a related operation at the end of last year's “Final Operation”, investigators had found that more than 100,000 encrypted wallet log-in data had been stolen, but that part of the wallet had not yet been removed.
Additional information:Such strikes often make it difficult to put an end to the malicious software network once and for all, and the relevant operators are often reorganized in a short time. It was reported that StealC had issued a new version this month and that Europol and its partners were sending reminders to potential victims through services such as Have I Been Pwned.
