Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 79 IP / 51 hostnames
Amadey is a Windows malware family first observed in 2018 that is most commonly characterized as a bot or loader used to establish initial access, profile infected hosts, communicate with command-and-control infrastructure, and retrieve and execute additional payloads.
Profile source: Mallory opens in a new tabAmadey
Amadey is a Windows malware family first observed in 2018 that is most commonly characterized as a bot or loader used to establish initial access, profile infected hosts, communicate with command-and-control infrastructure, and retrieve and execute additional payloads. It has been widely used in criminal operations as a delivery platform for infostealers, proxy malware, cryptominers, and ransomware, and has also appeared in activity linked to groups including TA505, Kimsuky, and campaigns associated with RokRAT delivery chains. A Microsoft-led disruption effort targeting Amadey infrastructure was announced in June 2026 with support from law enforcement and private-sector partners.
On infected systems, Amadey gathers host information such as username, hostname, operating system details, architecture, privilege level, and installed security products, then sends this data to its command-and-control server. Observed variants use HTTP POST for beaconing and tasking, and later versions have been documented using RC4-encrypted binary data encoded as hexadecimal strings in command-and-control exchanges. Amadey can download and execute additional payloads, including both executable and DLL modules, and has been used as a staging mechanism for follow-on malware families such as RedLine, StealC, Lumma, and ransomware.
Amadey supports persistence and defense-evasion behavior. Reported samples have established persistence through scheduled tasks and Startup-folder related user shell configuration changes. The malware has also been observed checking for antivirus products, and some analyzed samples exposed functionality associated with privilege escalation and execution through trusted Windows utilities. In some campaigns, Amadey or its plugins have stolen browser credentials and other sensitive data, including Outlook profile information, MikroTik Winbox data, and cryptocurrency wallet-related information. Plugin-based extensions have also enabled clipboard hijacking for cryptocurrency theft and broader credential harvesting.
Delivery has been observed through multiple vectors, including phishing emails, malicious documents, fake cheat or software-download sites, bundled cracked or pirated software, and exploit-based delivery. Amadey has also been distributed through pay-per-install ecosystems such as PrivateLoader and has itself functioned as a pay-per-install or loader component in broader malware distribution chains. Long-term observation of its infrastructure indicates a large and active ecosystem with many short-lived command-and-control servers and substantial growth in the volume of secondary payloads delivered over time.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 d780677e97da00b2b90849741720c1a02e758356630b63242a18074775c69e1c 4fd1c54721daab35efde396d8ddea46ce8c49f14b45ec8aad8808d1cd1d16097 5b166cf621fa4e005932e9ca0146e0b1d24564a619da5a525e1a16099c95b98b c9cc24b62aa3f6eb41a343f5152750babaa0c4d48f7ab772a4c81922382c2da7 d3ab87707629064a3dbcd7ae00afd598b73479f9e84b4248b7f26a47eedb609a f708c405d13450a3886936d68e63ad841836d0a741fb6848fd7b58c83db988d2 Reported operators
Un lien similaire a aussi été constaté par le CERT sud-coréen entre une souche du rançongiciel et une souche du code Amadey qui, bien que vendu sur certains forum d’attaquants, est aussi utilisé par TA505.
TA406 has used many different malware families, including KONNI, SANNY, CARROTBAT/CARROTBALL, BabyShark, Amadey and Android Moez.
The Amadey bot is a Trojan that was first discovered in 2018 and is used to steal sensitive information from the infected device.
During our analysis of the ROKRAT infection chain, we came across a similar chain leading to the deployment of Amadey, a commercial RAT sold in underground forums.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Amadey (loader/bot)
Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. ... SocGholish and Amadey function as loaders for introducing next-stage malware ... A C++-based modular backdoor, it's known to be active since October 2018 and advertised by a threat actor known as InCrease.
References https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
Exploited software
MITRE ATT&CK
Reporting
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.