Last seven days
- First activity
- Jul 13, 2026
- Last activity
- Jul 19, 2026
- Feed role
- C2
- Host form
- 15 IP / 26 hostnames
Amadey is a Windows malware family and malware-as-a-service offering active since at least 2018, primarily used as a loader and dropper to establish initial access and deliver additional payloads.
Profile source: Mallory opens in a new tabAmadey
Amadey is a Windows malware family and malware-as-a-service offering active since at least 2018, primarily used as a loader and dropper to establish initial access and deliver additional payloads. It is commonly positioned early in intrusion chains, where it compromises systems, profiles infected hosts, persists locally, and retrieves follow-on malware such as infostealers, remote access trojans, clippers, and ransomware. Amadey has also been described as having information-stealing functionality, including collection of sensitive system and user data from infected devices.
Operationally, Amadey is frequently associated with broader cybercrime ecosystems and has been repeatedly observed delivering or appearing alongside malware such as StealC, RedLine, Lumma, Rhadamanthys, TinyLoader, and other commodity crimeware. Multiple investigations have linked Amadey and StealC through shared backend infrastructure, and coordinated law-enforcement actions under Operation Endgame disrupted infrastructure used by both malware operations. Amadey has also been referenced in activity associated with Kimsuky-linked tooling.
Technically, Amadey is modular and supports downloading and executing secondary payloads after host reconnaissance. Reported behavior includes security software discovery, persistence through Windows Registry modification and scheduled tasks, and encrypted communications using RC4. It has been observed collecting host profiling data and checking for installed antivirus products before proceeding with follow-on activity. In some campaigns, operators abused legitimate online services and development platforms to host payloads or store victim system information.
Distribution has been strongly associated with phishing campaigns, and Amadey is widely used as an entry-point malware component in financially motivated attacks, credential theft operations, and ransomware deployment chains. Its role as a reusable initial-access and payload-delivery service has made it a persistent fixture in the commodity malware ecosystem targeting Windows systems.
C2 tracking
Derp observations, rolling seven-day window
Samples
e4211d0e545311bb60f65f15404c590ce1a0ef4db12ce470e492d7975d3e7b6d 35c93c643baf3be8c08584d59d11a9b60c8064a38f43affd560d839c7372c9e8 730d98fa5a62ef7fcb77afa3c669b816a9b21e64157fa98aeefc5bfb3ac0cebc 8211468fff3cd6cf858f652b53db995782d573a092d00dac648b863d1b237efd 8aa655f97cac46746b82b6dfc7ed9742c68970d802f57625fc01bca88b14a359 de52cc2c509c641cf95865a6b64d0fa6a85feafd56533ee349407a3d005872c9 3a410c1cd84f6b3729c6480c7db0d861f3832d1607581319026e0b4987d3c519 a86c023a02f1454738b39f753f50777c238b4ea296ffc76cd41c3059f216be10 aff6939cc1b99ac0747bed804ab91c8b752f4b0cdef5f516f220f070eb5fd26b b9d13b2831bae0b3d21340f846f80ed3ff7ae372e05206bdb791e9eb435b499f Reported operators
AutoIt을 사용해 악성코드를 제작하는 Kimsuky 그룹 (RftRAT, Amadey)
Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. ... SocGholish and Amadey function as loaders for introducing next-stage malware ... A C++-based modular backdoor, it's known to be active since October 2018 and advertised by a threat actor known as InCrease.
References https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
MITRE ATT&CK
Reporting
The first tool is called Amadey, a malware-as-a-service platform for disrupting devices and deploying infected payloads for ransomware and related attacks.
Amadey2
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
В рамках международной операции Endgame правоохранительные органы и специалисты ИБ-компаний нарушили работу инфраструктуры, которую использовали операторы загрузчика Amadey и инфостилера StealC.
L’agence européenne de police a en effet annoncé le démantèlement d’une infrastructure criminelle plus large comprenant également les dropper Amadey et SocGholish.
Amadey: Gave attackers initial access to targeted systems and allowed additional malware to be installed.
Amadey is another MaaS offering and loader that is frequently used to deliver StealC.
Meanwhile, the Amadey dropper/loader is spread mostly through phishing campaigns, introducing extra malware into compromised systems and retrieving sensitive data.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.