Amadey is a Windows loader and botnet; StealC is an information stealer. This June 2026 Bitsight TRACE publication describes the team’s threat intelligence supporting a coordinated disruption led by Europol and the Microsoft Digital Crimes Unit.

The research connects sample hunting and configuration extraction with C2 protocol emulation, sinkholing, and published YARA and Suricata rules. It explains how these methods expose infrastructure and follow-up payloads. The infection figures reflect specific collection sources and time windows, rather than the complete botnet populations.

The publication credits the contribution collectively to Bitsight TRACE and describes the roles of the wider public-private partnership.

Read the original article at Bitsight