Last seven days
- First activity
- Aug 31, 2026
- Last activity
- Sep 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 25 IP / 13 hostnames
FlawedAmmyy is a Windows remote access trojan derived from leaked source code of the legitimate Ammyy Admin remote-administration tool and first observed in 2016.
Profile source: Mallory opens in a new tabFlawedAmmyy
FlawedAmmyy is a Windows remote access trojan derived from leaked source code of the legitimate Ammyy Admin remote-administration tool and first observed in 2016. It is a full-featured RAT used in financially motivated intrusion activity, most notably by TA505, and has also been observed in delivery chains involving Necurs, Amadey, and AndroMut. It has been associated with enterprise intrusions that later led to Clop ransomware deployment, including operations targeting financial institutions, government entities, and other organizations across multiple regions.
The malware supports broad post-compromise control and collection functions. Reported capabilities include command execution through PowerShell and the Windows command shell, file upload and download, screenshot capture, clipboard collection, keylogging, mouse-event collection, host reconnaissance, and exfiltration over its command-and-control channel. During initial execution it can enumerate the current user, privilege level, operating system, computer name, and installed antivirus products, including via Windows Management Instrumentation, and it can check for smart-card presence. FlawedAmmyy has used HTTP for command and control and has been observed using SEAL encryption and handshake obfuscation during initial communications.
Persistence has been established through the Windows Run key, and execution has been observed via common Windows utilities including msiexec and rundll32. The malware has also been reported deleting files through batch-script execution as part of cleanup or defense-evasion behavior. In some campaigns, FlawedAmmyy was delivered through phishing-driven infection chains using malicious Office documents, HTML or ISO lures, macro-enabled files, MSI installers, and intermediate downloaders. TA505 notably used it as a second-stage payload in campaigns that evolved from broad email distribution into hands-on intrusions with lateral movement and eventual ransomware deployment.
FlawedAmmyy is widely regarded as one of the characteristic TA505 backdoors of the late 2010s and an important component in the group’s transition from mass-malspam operations to more targeted enterprise compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
0210f19ad6b72c8860d9e88b31c546a39a47939ded2bf91c65738b7ffdcf913c 2070e2483590dd3b6ccbe4339d29c095edbbc4cadd6b57dac3ec006ff76c7bbc 2306b3a8fa9e128165239c731a1413fd525cf97a862a98de88a678a4fabf1571 91a6876dc164712f87abd2d159c0ae8af59a528478a13653f67c33ecbf9c628f 94ca739eb8986f3005ac02f028e5bb23f872a4d24f9ad8c1f96100ff0ebab4c6 265ff3e568105a01f8c6d52912715be58f550096b12332fdc86c7c4e80746323 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 3a297d846199ddff323b30eadb510daedbbd08a9e76949c06df09e1592dd0f02 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6370953f49bf9c07f989500b7f6a0d84f4fefaf8e002770cde236f7f494f48c0 Reported operators
...or less widely distributed malware like FlawedAmmyy at scale following similar tests.
Finding Grace as a payload is interesting, as it is known to be almost exclusively used by TA505, which further strengthens previous claims of a connection between Silence Group and TA505 made by Group-IB, which was based on source code comparison with FlawedAmmyy.
MITRE ATT&CK
Reporting
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.