INTEL_REPORT
ESET WeLiveSecurity · published 6/24/2026, 12:35:24 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights ESET takes part in Operation Endgame to disrupt Amadey and Stealc Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH A…
https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc
sha256:0fd152b0e16ef64a84fb9d45fe658a01da29e8fa3eb4a43db53a81c57bb623e4
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| ip | 176.124.199.207 | Open → |
| ip | 194.26.192.191 | Open → |
| ip | 196.251.107.130 | Open → |
| domain | flare.io | Open → |
| domain | 07.exe | Open → |
| domain | yinkaroj.exe | Open → |
| domain | ion.exe | Open → |
| domain | patch.exe | Open → |
| domain | spy.agent.qol | Open → |
| domain | der.amadey | Open → |
| domain | mi.overlapsno | Open → |
| domain | wbound.com | Open → |