Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 34 IP / 57 hostnames
Amadey is a malware-as-a-service loader and dropper first observed in 2018 and widely used as an initial-access component in cybercrime operations.
Profile source: Mallory opens in a new tabAmadey
Amadey is a malware-as-a-service loader and dropper first observed in 2018 and widely used as an initial-access component in cybercrime operations. It is primarily associated with Windows infections and is commonly used to compromise devices, establish persistence, profile the host, and deploy additional payloads including infostealers, remote access trojans, cryptominers, and ransomware. Amadey has repeatedly appeared in multi-stage intrusion chains alongside malware such as StealC and other commodity crimeware, making it a frequent enabler of credential theft, fraud, and downstream extortion activity.
The malware is mainly distributed through phishing campaigns, though it has also appeared in broader malware delivery ecosystems and bundled attack chains. Once executed, Amadey can persist on the infected system through registry modification and has been observed checking for installed antivirus products, indicating host reconnaissance and defense-evasion behavior before or during follow-on activity. It can retrieve sensitive information from compromised systems in addition to functioning as a payload delivery mechanism.
Operational reporting has linked Amadey to shared criminal infrastructure used with the StealC infostealer, and international law-enforcement actions under Operation Endgame disrupted infrastructure supporting both malware families. Amadey has also been referenced in activity associated with Kimsuky-linked intrusion chains, though its broader use is consistent with commodity cybercrime rather than exclusive use by a single threat actor. Its role in providing initial access and installing secondary malware has made it a recurring first-stage tool in financially motivated attacks against a wide range of victims.
C2 tracking
Derp observations, rolling seven-day window
Samples
27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 142cc262204c457812ec32b653409bb63d0a2d1e0b2a1086076203b0dc08da93 3cd3f52a4b0023bc1e493b5b07b14c143aedb0e4a949e035a4896079e06c39a8 55a5d9abf4db337bf07f130b6d92778cc4b6887f79d62f738c3a213c2ea75ffc 823cd9084fc77a563f63df16fdf47013bc59087f54563c26acc808bf27803d0d bbd29056c163e8eb6832db56c1dee080828430295e942c148ed19ef5231d172a Reported operators
AutoIt을 사용해 악성코드를 제작하는 Kimsuky 그룹 (RftRAT, Amadey)
Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. ... SocGholish and Amadey function as loaders for introducing next-stage malware ... A C++-based modular backdoor, it's known to be active since October 2018 and advertised by a threat actor known as InCrease.
References https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
MITRE ATT&CK
Reporting
Commodity-Payload Command-and-Control, Distribution and Dead-Drop Resolvers (Delivered Malware) Amadey / Loader Panels: wfsdragon.ru/api/setStats.php
The first tool is called Amadey, a malware-as-a-service platform for disrupting devices and deploying infected payloads for ransomware and related attacks.
Amadey2
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
В рамках международной операции Endgame правоохранительные органы и специалисты ИБ-компаний нарушили работу инфраструктуры, которую использовали операторы загрузчика Amadey и инфостилера StealC.
L’agence européenne de police a en effet annoncé le démantèlement d’une infrastructure criminelle plus large comprenant également les dropper Amadey et SocGholish.
Amadey: Gave attackers initial access to targeted systems and allowed additional malware to be installed.
Amadey is another MaaS offering and loader that is frequently used to deliver StealC.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.