Amadey is a modular malware loader and botnet ecosystem active since 2018 and commonly used as a malware distribution service. It has been advertised on darknet forums under the name InCrease and is sold in a pay-per-rebuild model in which customers operate their own self-hosted administration panels and command-and-control infrastructure. The malware’s primary role is to deliver additional payloads to compromised systems, but the platform also supports modules for credential theft, clipboard monitoring, VNC-based remote access, and other post-compromise functions. Amadey operates as a fragmented malware-as-a-service and pay-per-install ecosystem rather than a centrally managed botnet. Multiple affiliate clusters have been identified, each using distinct infrastructure and build characteristics. One especially large cluster functioned as a broad distribution service and repeatedly delivered multiple payloads per victim, including infostealers from different affiliates. Amadey has been used to distribute a wide range of commodity malware, including infostealers, remote access trojans, cryptominers, and other loaders. Observed delivery methods include fake software updates, cracked software installers, and third-party malware loaders. In active campaigns, Amadey has also been used to deploy legitimate remote management and monitoring tools as persistent backdoors by abusing normal vendor provisioning workflows rather than trojanizing the software itself. Such campaigns have shown tradecraft consistent with initial access brokerage and financially motivated intrusion activity, combining malware delivery with redundant persistence and follow-on monetization. Technical reporting describes Amadey as a modular loader that communicates with command-and-control servers over HTTP POST using RC4-encrypted traffic and a staged lifecycle for beaconing, registration, and tasking. Later versions added expanded remote access and execution features, including hidden VNC, silent installer support, remote desktop enabling, SYSTEM-level command execution, and support for encrypted payloads. Amadey has been disrupted in coordinated operations targeting affiliate infrastructure, reflecting its broad use in criminal malware distribution. Its ecosystem has also been closely tied to infostealer operations, including campaigns delivering Lumma Stealer and other credential-focused malware. Overall, Amadey is best characterized as a financially motivated criminal loader and pay-per-install service that enables initial access, malware deployment, persistence, credential theft, and broader post-exploitation activity across a globally distributed affiliate base.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pay-per-install service used to deliver infostealer payloads whose activity declined alongside Lumma Stealer’s drop in volume.
Malware-as-a-service loader ecosystem whose affiliates operate their own C2 infrastructure and use it to distribute additional malware, exfiltrate data, and enable remote access. The report discusses disruption of Amadey infrastructure and clustering of affiliate-operated botnets.
Conducting a multi-stage botnet campaign that delivers stealers, RATs, and legitimate RMM tools for persistent access, with likely monetization through access sales, ransomware affiliate activity, or cryptomining.
Botnet/BaaS staging operation distributing numerous commodity malware families for multiple customers through a shared upstream provider also linked to evilgrou-tech infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.