Skip to content
Malware family

FlawedAmmyy

FlawedAmmyy is a remote access Trojan (RAT) discovered by Proofpoint and used since at least early 2016 in both highly targeted email attacks and large-scale malspam campaigns.

Profile source: Mallory opens in a new tab

FlawedAmmyy

Family profile

FlawedAmmyy is a remote access Trojan (RAT) discovered by Proofpoint and used since at least early 2016 in both highly targeted email attacks and large-scale malspam campaigns. It is based on leaked source code from Version 3 of the Ammyy Admin remote desktop software. Reported capabilities include remote desktop control, file system management, proxy support, audio chat, screenshot capture, clipboard collection, keylogging, command execution via PowerShell, and exfiltration of collected data to command-and-control (C2) servers. During initial profiling it enumerates the current user, leverages WMI to identify installed antivirus products, and checks whether a usable smart card is inserted in a reader. FlawedAmmyy communicates with C2 over HTTP on port 443; Proofpoint reported that its initial handshake uses SEAL-encrypted data, after which the malware sends host profiling information including OS version, privilege level, username, computer name, antivirus product, smart-card presence, and malware build time. Observed delivery vectors include macro-enabled Microsoft Word and Excel attachments, ZIP archives containing .url Internet Shortcut files that retrieved JavaScript over SMB, and infection chains involving Quant Loader and Get2 as intermediate downloaders. Proofpoint associated major FlawedAmmyy distribution activity with TA505, including Japan-focused campaigns and broader mass-email operations; targeted activity included the automotive sector. Additional observed execution details include installation via msiexec.exe. Reported infrastructure and payload indicators from Proofpoint include C2 endpoints 179.60.146.3:443 and 194.165.16.11:443, SMB URL file://buyviagraoverthecounterusabb.net/documents/B123456789012.js, Quant Loader URL hxxp://wassronledorhad.in/q2/index.php, and payload URL hxxp://balzantruck.com/45rt.exe.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 23, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • DE3

Leading providers

  • Hetzner Online GmbH3

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TA505

Get2 was, in turn, observed downloading FlawedGrace, FlawedAmmyy, Snatch, and SDBbot (a new RAT) as secondary payloads.

MITRE ATT&CK

FlawedAmmyy in ATT&CK

37 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.