Skip to content

Amadey

Amadey is a Windows malware family first observed in 2018 that is most commonly characterized as a bot or loader used to establish initial access, profile infected hosts, communicate with command-and-control infrastructure, and retrieve and execute additional payloads.

Profile source: Mallory opens in a new tab

Amadey

Family profile

Amadey is a Windows malware family first observed in 2018 that is most commonly characterized as a bot or loader used to establish initial access, profile infected hosts, communicate with command-and-control infrastructure, and retrieve and execute additional payloads. It has been widely used in criminal operations as a delivery platform for infostealers, proxy malware, cryptominers, and ransomware, and has also appeared in activity linked to groups including TA505, Kimsuky, and campaigns associated with RokRAT delivery chains. A Microsoft-led disruption effort targeting Amadey infrastructure was announced in June 2026 with support from law enforcement and private-sector partners.

On infected systems, Amadey gathers host information such as username, hostname, operating system details, architecture, privilege level, and installed security products, then sends this data to its command-and-control server. Observed variants use HTTP POST for beaconing and tasking, and later versions have been documented using RC4-encrypted binary data encoded as hexadecimal strings in command-and-control exchanges. Amadey can download and execute additional payloads, including both executable and DLL modules, and has been used as a staging mechanism for follow-on malware families such as RedLine, StealC, Lumma, and ransomware.

Amadey supports persistence and defense-evasion behavior. Reported samples have established persistence through scheduled tasks and Startup-folder related user shell configuration changes. The malware has also been observed checking for antivirus products, and some analyzed samples exposed functionality associated with privilege escalation and execution through trusted Windows utilities. In some campaigns, Amadey or its plugins have stolen browser credentials and other sensitive data, including Outlook profile information, MikroTik Winbox data, and cryptocurrency wallet-related information. Plugin-based extensions have also enabled clipboard hijacking for cryptocurrency theft and broader credential harvesting.

Delivery has been observed through multiple vectors, including phishing emails, malicious documents, fake cheat or software-download sites, bundled cracked or pirated software, and exploit-based delivery. Amadey has also been distributed through pay-per-install ecosystems such as PrivateLoader and has itself functioned as a pay-per-install or loader component in broader malware distribution chains. Long-term observation of its infrastructure indicates a large and active ecosystem with many short-lived command-and-control servers and substantial growth in the volume of secondary payloads delivered over time.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Privilege Escalation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Sep 3, 2026
Feed role
C2 / Distribution
Host form
79 IP / 51 hostnames

Leading locations

  • US29
  • DE22
  • NL15
  • CN13
  • HK11
  • RU5
  • LU4
  • KR3
  • SG3
  • GB2
  • TH2
  • CA1

Leading providers

  • FEMO IT SOLUTIONS LIMITED11
  • Omegatech LTD9
  • CTG Server Limited7
  • Hangzhou Alibaba Advertising Co.,Ltd.6
  • Microsoft Corporation6
  • HostPapa5

Infrastructure traits

  • Hosting 111
  • Anycast 3

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
TA505

Un lien similaire a aussi été constaté par le CERT sud-coréen entre une souche du rançongiciel et une souche du code Amadey qui, bien que vendu sur certains forum d’attaquants, est aussi utilisé par TA505.

Kimsuky

TA406 has used many different malware families, including KONNI, SANNY, CARROTBAT/CARROTBALL, BabyShark, Amadey and Android Moez.

LockBit

The Amadey bot is a Trojan that was first discovered in 2018 and is used to steal sensitive information from the infected device.

APT37

During our analysis of the ROKRAT infection chain, we came across a similar chain leading to the deployment of Amadey, a commercial RAT sold in underground forums.

Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Amadey (loader/bot)

Turla

Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.

InCrease

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. ... SocGholish and Amadey function as loaders for introducing next-stage malware ... A C++-based modular backdoor, it's known to be active since October 2018 and advertised by a threat actor known as InCrease.

WIZARD SPIDER

References https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey

Exploited software

Vulnerabilities linked to Amadey

1 CVEs

MITRE ATT&CK

Amadey in ATT&CK

111 distinct techniques

Techniques

111 techniques
T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1203 Exploitation for Client Execution T1566 Phishing T1082 System Information Discovery T1189 Drive-by Compromise T1027.013 Encrypted/Encoded File T1518.001 Security Software Discovery T1033 System Owner/User Discovery T1112 Modify Registry T1218.007 Msiexec T1498 Network Denial of Service T1053.005 Scheduled Task T1553.002 Code Signing T1059.005 Visual Basic T1027.002 Software Packing T1548.002 Bypass User Account Control T1547.001 Registry Run Keys / Startup Folder T1204.002 Malicious File T1480.002 Mutual Exclusion T1059.003 Windows Command Shell T1497.001 System Checks T1106 Native API T1555.005 Password Managers T1012 Query Registry T1218.011 Rundll32 T1115 Clipboard Data T1140 Deobfuscate/Decode Files or Information T1649 Steal or Forge Authentication Certificates T1070.004 File Deletion T1555.003 Credentials from Web Browsers T1552.001 Credentials In Files T1555 Credentials from Password Stores T1053 Scheduled Task/Job T1071.001 Web Protocols T1552.002 Credentials in Registry T1059 Command and Scripting Interpreter T1518 Software Discovery T1055 Process Injection T1568 Dynamic Resolution T1056 Input Capture T1027 Obfuscated Files or Information T1059.001 PowerShell T1047 Windows Management Instrumentation T1497 Virtualization/Sandbox Evasion T1041 Exfiltration Over C2 Channel T1548 Abuse Elevation Control Mechanism T1219 Remote Access Tools T1560 Archive Collected Data T1204 User Execution T1095 Non-Application Layer Protocol T1087 Account Discovery T1222 File and Directory Permissions Modification T1113 Screen Capture T1003 OS Credential Dumping T1547 Boot or Logon Autostart Execution T1213 Data from Information Repositories T1566.002 Spearphishing Link T1566.001 Spearphishing Attachment T1083 File and Directory Discovery T1571 Non-Standard Port T1562 Impair Defenses T1190 Exploit Public-Facing Application T1070 Indicator Removal T1005 Data from Local System T1550 Use Alternate Authentication Material T1583 Acquire Infrastructure T1587.001 Malware T1001 Data Obfuscation T1036 Masquerading T1543 Create or Modify System Process T1218 System Binary Proxy Execution T1537 Transfer Data to Cloud Account T1078 Valid Accounts T1564.003 Hidden Window T1562.001 Disable or Modify Tools T1195 Supply Chain Compromise T1090 Proxy T1020 Automated Exfiltration T1127 Trusted Developer Utilities Proxy Execution T1057 Process Discovery T1027.015 Compression T1016 System Network Configuration Discovery T1136.001 Local Account T1132.001 Standard Encoding T1119 Automated Collection T1614.001 System Language Discovery T1008 Fallback Channels T1583.004 Server T1055.002 Portable Executable Injection T1219.002 Remote Desktop Software T1573 Encrypted Channel T1480 Execution Guardrails T1021.005 VNC T1573.001 Symmetric Cryptography T1588.001 Malware T1129 Shared Modules T1608.001 Upload Malware T1584 Compromise Infrastructure T1021.001 Remote Desktop Protocol T1543.003 Windows Service T1204.003 Malicious Image T1059.006 Python T1583.001 Domains T1036.005 Match Legitimate Resource Name or Location T1569 System Services T1055.012 Process Hollowing T1036.001 Invalid Code Signature T1588.002 Tool T1583.005 Botnet T1608 Stage Capabilities

Reporting

Research mentioning Amadey

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Aug 3
Malware News

Cyber Conflict Briefing Q2 2026 - Malware Analysis - Malware Analysis, News and Indicators

The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.