Amber Albatross is a Red Canary-tracked activity cluster centered on malware delivery through installers masquerading as legitimate free software and potentially unwanted applications, ultimately leading to a PyInstaller-packed payload with stealer-like capabilities. The cluster has been repeatedly observed as a prevalent threat across 2024-2026 and significantly updated its tradecraft during 2025. Initial access commonly begins with adware-style or bundled-software delivery, including installers themed as utility software such as PDF tools. The intrusion chain progresses through multiple stages and has used code-signed installers, rotating lure themes, anti-sandbox behavior, and required command-line arguments to hinder automated analysis. Later-stage delivery evolved to include Base64-encoded PowerShell used to download and execute additional payloads, and some second- and third-stage components migrated from C++ to Go. The final-stage PyInstaller payload has been protected with Pyarmor to obstruct static analysis. Post-delivery behavior is consistent with reconnaissance and credential-access objectives typical of information stealers. Observed functionality includes hypervisor detection, system profiling, enumeration of endpoint manufacturer, model, installed updates, installed software, antivirus and firewall products, and discovery of installed browsers. The malware attempts to access browser profile or user-data locations and checks whether Chrome may be enterprise-managed, indicating interest in browser-resident data and potentially corporate browsing environments. The exact downstream use of some collected environment information remains undetermined, but the cluster is consistently characterized as having stealer capabilities. Known aliases are limited to the name Amber Albatross itself; it is a vendor-assigned cluster name rather than a publicly established nation-state designation. Available information supports classification as a malware delivery and theft-oriented criminal activity cluster rather than espionage infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage activity cluster delivered via trojanized installers masquerading as free software, culminating in a stealer-capable PyInstaller executable.
A Red Canary-named threat cluster whose tradecraft was significantly updated in 2025 and which ranked as the number 1 threat in the report.
Uses masquerading malware/PUP-style installers themed as PDF utilities to deliver a PyArmor-protected PyInstaller payload that performs host and browser reconnaissance, with anti-analysis and anti-sandbox measures.
Mentioned as a prevalent named activity cluster on the July threat list, but no further operational detail is provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.