Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 23, 2026
- Feed role
- C2
- Host form
- 3 IP / 0 hostnames
FlawedAmmyy is a remote access Trojan (RAT) discovered by Proofpoint and used since at least early 2016 in both highly targeted email attacks and large-scale malspam campaigns.
Profile source: Mallory opens in a new tabFlawedAmmyy
FlawedAmmyy is a remote access Trojan (RAT) discovered by Proofpoint and used since at least early 2016 in both highly targeted email attacks and large-scale malspam campaigns. It is based on leaked source code from Version 3 of the Ammyy Admin remote desktop software. Reported capabilities include remote desktop control, file system management, proxy support, audio chat, screenshot capture, clipboard collection, keylogging, command execution via PowerShell, and exfiltration of collected data to command-and-control (C2) servers. During initial profiling it enumerates the current user, leverages WMI to identify installed antivirus products, and checks whether a usable smart card is inserted in a reader. FlawedAmmyy communicates with C2 over HTTP on port 443; Proofpoint reported that its initial handshake uses SEAL-encrypted data, after which the malware sends host profiling information including OS version, privilege level, username, computer name, antivirus product, smart-card presence, and malware build time. Observed delivery vectors include macro-enabled Microsoft Word and Excel attachments, ZIP archives containing .url Internet Shortcut files that retrieved JavaScript over SMB, and infection chains involving Quant Loader and Get2 as intermediate downloaders. Proofpoint associated major FlawedAmmyy distribution activity with TA505, including Japan-focused campaigns and broader mass-email operations; targeted activity included the automotive sector. Additional observed execution details include installation via msiexec.exe. Reported infrastructure and payload indicators from Proofpoint include C2 endpoints 179.60.146.3:443 and 194.165.16.11:443, SMB URL file://buyviagraoverthecounterusabb.net/documents/B123456789012.js, Quant Loader URL hxxp://wassronledorhad.in/q2/index.php, and payload URL hxxp://balzantruck.com/45rt.exe.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Get2 was, in turn, observed downloading FlawedGrace, FlawedAmmyy, Snatch, and SDBbot (a new RAT) as secondary payloads.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.