StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
2026-06-24T14:52:20Z•6bb7d6371c40d273584052a0ba2026eaec884e6747c06a27ef03d39e4138d1dc
AI browsing agentAmadeyAutoGen StudioAutoJackEDRMCP WebSocketMDASHMastraMicrosoft DCURCESapphire SleetStealCTor C2agentic vulnerability detectionbackdoorclipboard theftcrypto clipperinfostealerlocalhost trustnpmpostinstall payloadsupply chainsupply‑chain compromisetakedownworm‑like propagation
What happened
Microsoft Security Blog posts (June 2026) describe multiple active and emergent threats and defensive advances: a coordinated Microsoft DCU takedown of domains supporting the StealC and Amadey infostealer infrastructures; AutoJack, a novel exploit chain that can achieve remote code execution on a host by abusing AI browsing agents (localhost trust, missing auth, unsafe parameters via AutoGen Studio’s MCP WebSocket); a malicious Mastra npm postinstall supply‑chain compromise attributed to Sapphire Sleet that infected 140+ projects; a crypto‑clipper campaign using Tor for C2 and worm‑like self‑‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 6bb7d6371c40d273584052a0ba2026eaec884e6747c06a27ef03d39e4138d1dc
- Enrichment time
- 2026-06-24T14:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.