Skip to content

FlawedAmmyy

FlawedAmmyy is a Windows remote access trojan derived from leaked source code of the legitimate Ammyy Admin remote-administration tool and first observed in 2016.

Profile source: Mallory opens in a new tab

FlawedAmmyy

Family profile

FlawedAmmyy is a Windows remote access trojan derived from leaked source code of the legitimate Ammyy Admin remote-administration tool and first observed in 2016. It is a full-featured RAT used in financially motivated intrusion activity, most notably by TA505, and has also been observed in delivery chains involving Necurs, Amadey, and AndroMut. It has been associated with enterprise intrusions that later led to Clop ransomware deployment, including operations targeting financial institutions, government entities, and other organizations across multiple regions.

The malware supports broad post-compromise control and collection functions. Reported capabilities include command execution through PowerShell and the Windows command shell, file upload and download, screenshot capture, clipboard collection, keylogging, mouse-event collection, host reconnaissance, and exfiltration over its command-and-control channel. During initial execution it can enumerate the current user, privilege level, operating system, computer name, and installed antivirus products, including via Windows Management Instrumentation, and it can check for smart-card presence. FlawedAmmyy has used HTTP for command and control and has been observed using SEAL encryption and handshake obfuscation during initial communications.

Persistence has been established through the Windows Run key, and execution has been observed via common Windows utilities including msiexec and rundll32. The malware has also been reported deleting files through batch-script execution as part of cleanup or defense-evasion behavior. In some campaigns, FlawedAmmyy was delivered through phishing-driven infection chains using malicious Office documents, HTML or ISO lures, macro-enabled files, MSI installers, and intermediate downloaders. TA505 notably used it as a second-stage payload in campaigns that evolved from broad email distribution into hands-on intrusions with lateral movement and eventual ransomware deployment.

FlawedAmmyy is widely regarded as one of the characteristic TA505 backdoors of the late 2010s and an important component in the group’s transition from mass-malspam operations to more targeted enterprise compromise.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 31, 2026
Last activity
Sep 6, 2026
Feed role
C2 / Distribution
Host form
25 IP / 13 hostnames

Leading locations

  • DE9
  • CN8
  • US8
  • KR3
  • NL3
  • BR1
  • ES1
  • FR1
  • IN1
  • JP1
  • RU1
  • SG1

Leading providers

  • FEMO IT SOLUTIONS LIMITED6
  • Cloudflare, Inc.4
  • Omegatech LTD4
  • CHINA UNICOM China169 Backbone3
  • Amazon.com, Inc.2
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch2

Infrastructure traits

  • Hosting 28
  • Anycast 4
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA505

...or less widely distributed malware like FlawedAmmyy at scale following similar tests.

Silence

Finding Grace as a payload is interesting, as it is known to be almost exclusively used by TA505, which further strengthens previous claims of a connection between Silence Group and TA505 made by Group-IB, which was based on source code comparison with FlawedAmmyy.

MITRE ATT&CK

FlawedAmmyy in ATT&CK

49 distinct techniques

Reporting

Research mentioning FlawedAmmyy

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Apr 19
Bleeping Computer

March 2023 broke ransomware attack records with 459 incidents

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.