Skip to content
Malware family Windows

Amadey

Amadey is a Windows malware family and malware-as-a-service offering active since at least 2018, primarily used as a loader and dropper to establish initial access and deliver additional payloads.

Profile source: Mallory opens in a new tab

Amadey

Family profile

Amadey is a Windows malware family and malware-as-a-service offering active since at least 2018, primarily used as a loader and dropper to establish initial access and deliver additional payloads. It is commonly positioned early in intrusion chains, where it compromises systems, profiles infected hosts, persists locally, and retrieves follow-on malware such as infostealers, remote access trojans, clippers, and ransomware. Amadey has also been described as having information-stealing functionality, including collection of sensitive system and user data from infected devices.

Operationally, Amadey is frequently associated with broader cybercrime ecosystems and has been repeatedly observed delivering or appearing alongside malware such as StealC, RedLine, Lumma, Rhadamanthys, TinyLoader, and other commodity crimeware. Multiple investigations have linked Amadey and StealC through shared backend infrastructure, and coordinated law-enforcement actions under Operation Endgame disrupted infrastructure used by both malware operations. Amadey has also been referenced in activity associated with Kimsuky-linked tooling.

Technically, Amadey is modular and supports downloading and executing secondary payloads after host reconnaissance. Reported behavior includes security software discovery, persistence through Windows Registry modification and scheduled tasks, and encrypted communications using RC4. It has been observed collecting host profiling data and checking for installed antivirus products before proceeding with follow-on activity. In some campaigns, operators abused legitimate online services and development platforms to host payloads or store victim system information.

Distribution has been strongly associated with phishing campaigns, and Amadey is widely used as an entry-point malware component in financially motivated attacks, credential theft operations, and ransomware deployment chains. Its role as a reusable initial-access and payload-delivery service has made it a persistent fixture in the commodity malware ecosystem targeting Windows systems.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 13, 2026
Last activity
Jul 19, 2026
Feed role
C2
Host form
15 IP / 26 hostnames

Leading locations

  • US20
  • DE8
  • NL4
  • SC3
  • IE2
  • IN1
  • LU1

Leading providers

  • Microsoft Corporation12
  • Amazon.com, Inc.6
  • FEMO IT SOLUTIONS LIMITED6
  • Amazon.com, Inc.3
  • Omegatech LTD3
  • Baykov Ilya Sergeevich1

Infrastructure traits

  • Hosting 35
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
Kimsuky

AutoIt을 사용해 악성코드를 제작하는 Kimsuky 그룹 (RftRAT, Amadey)

Turla

Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.

InCrease

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. ... SocGholish and Amadey function as loaders for introducing next-stage malware ... A C++-based modular backdoor, it's known to be active since October 2018 and advertised by a threat actor known as InCrease.

WIZARD SPIDER

References https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey

MITRE ATT&CK

Amadey in ATT&CK

97 distinct techniques

Techniques

97 techniques
T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1112 Modify Registry T1082 System Information Discovery T1547.001 Registry Run Keys / Startup Folder T1518.001 Security Software Discovery T1027 Obfuscated Files or Information T1204.002 Malicious File T1587.001 Malware T1555 Credentials from Password Stores T1078 Valid Accounts T1189 Drive-by Compromise T1566 Phishing T1649 Steal or Forge Authentication Certificates T1041 Exfiltration Over C2 Channel T1005 Data from Local System T1012 Query Registry T1195 Supply Chain Compromise T1106 Native API T1218.011 Rundll32 T1140 Deobfuscate/Decode Files or Information T1033 System Owner/User Discovery T1083 File and Directory Discovery T1113 Screen Capture T1090 Proxy T1218.007 Msiexec T1547 Boot or Logon Autostart Execution T1020 Automated Exfiltration T1127 Trusted Developer Utilities Proxy Execution T1059.003 Windows Command Shell T1057 Process Discovery T1027.015 Compression T1059.001 PowerShell T1016 System Network Configuration Discovery T1071.001 Web Protocols T1115 Clipboard Data T1136.001 Local Account T1552.001 Credentials In Files T1132.001 Standard Encoding T1119 Automated Collection T1055 Process Injection T1053 Scheduled Task/Job T1614.001 System Language Discovery T1008 Fallback Channels T1583.004 Server T1055.002 Portable Executable Injection T1219.002 Remote Desktop Software T1497.001 System Checks T1573 Encrypted Channel T1480 Execution Guardrails T1021.005 VNC T1573.001 Symmetric Cryptography T1555.003 Credentials from Web Browsers T1552.002 Credentials in Registry T1588.001 Malware T1129 Shared Modules T1608.001 Upload Malware T1584 Compromise Infrastructure T1027.013 Encrypted/Encoded File T1003 OS Credential Dumping T1204 User Execution T1053.005 Scheduled Task T1021.001 Remote Desktop Protocol T1070.004 File Deletion T1560 Archive Collected Data T1219 Remote Access Tools T1543.003 Windows Service T1204.003 Malicious Image T1059 Command and Scripting Interpreter T1566.002 Spearphishing Link T1036 Masquerading T1059.006 Python T1583.001 Domains T1036.005 Match Legitimate Resource Name or Location T1562.001 Disable or Modify Tools T1218 System Binary Proxy Execution T1566.001 Spearphishing Attachment T1569 System Services T1055.012 Process Hollowing T1518 Software Discovery T1036.001 Invalid Code Signature T1588.002 Tool T1583.005 Botnet T1608 Stage Capabilities T1562 Impair Defenses T1056 Input Capture T1059.005 Visual Basic T1001 Data Obfuscation T1203 Exploitation for Client Execution T1070.006 Timestomp T1583.008 Malvertising T1583.006 Web Services T1614 System Location Discovery T1204.001 Malicious Link T1222.001 Windows File and Directory Permissions Modification T1568.001 Fast Flux DNS T1553.005 Mark-of-the-Web Bypass

Reporting

Research mentioning Amadey

Jul 12
Cysecurity News

Operation Endgame Disrupts Global Cyber Crime Assembly Line - CySecurity News - Latest Information Security and Hacking Incidents

The first tool is called Amadey, a malware-as-a-service platform for disrupting devices and deploying infected payloads for ransomware and related attacks.

Jul 7
Gurucul Threat Research

Millenium: A RAT Rewritten, a Threat Multiplied | Community Portal | Gurucul

Amadey2

Jun 29
Security Week

OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI - SecurityWeek

Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware

Jun 29
Xakep

Правоохранительные органы нарушили работу инфраструктуры малвари Amadey и StealC - Хакер

В рамках международной операции Endgame правоохранительные органы и специалисты ИБ-компаний нарушили работу инфраструктуры, которую использовали операторы загрузчика Amadey и инфостилера StealC.

Jun 26
Zdnet

Comment l’IA a permis de mettre en lumière les liens entre Amadey ...

L’agence européenne de police a en effet annoncé le démantèlement d’une infrastructure criminelle plus large comprenant également les dropper Amadey et SocGholish.

Jun 25
Techrepublic Com Security

Europol, Microsoft Hit Malware Network Behind 27M Stolen Logins, 140,000 Infected Computers

Amadey: Gave attackers initial access to targeted systems and allowed additional malware to be installed.

Jun 25
Scworld

StealC infrastructure takedown assisted by AI analysis, C2 infiltration | news | SC Media

Amadey is another MaaS offering and loader that is frequently used to deliver StealC.

Jun 25
Itpro

‘This operation marked a shift in strategy’: Three notorious malware networks have been taken down using RICO legislation | IT Pro

Meanwhile, the Amadey dropper/loader is spread mostly through phishing campaigns, introducing extra malware into compromised systems and retrieving sensitive data.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.