Amber Albatross is a Windows-focused malware activity cluster characterized by fake or masquerading software installers that ultimately deliver a PyInstaller-packaged payload with stealer capabilities. It has been associated with installers posing as legitimate free software and PDF-related utilities, as well as distribution through potentially unwanted programs. The intrusion chain commonly progresses through multiple stages, with operators periodically changing installer branding, code-signing identities, and intermediate payload implementations while preserving the same final objective.
Observed tradecraft includes staged payload retrieval and execution using Base64-encoded PowerShell, migration of some intermediate components from C++ to Go, and anti-analysis measures in both early and late stages. Early installers have shown anti-sandbox behavior, while later payloads have required specific command-line arguments to fully execute, reducing visibility in automated analysis environments. The final Python-based payload has also been protected with Pyarmor to hinder static analysis.
The terminal payload exhibits stealer-like reconnaissance behavior. It checks for virtualization, enumerates host characteristics and installed software updates, identifies security products such as antivirus and firewall tools, and searches for installed browsers including mainstream and Chromium-based variants. It then attempts to access browser profile or user data locations, indicating likely interest in browser-resident information. Some variants also inspect whether Chrome is enterprise-managed and enumerate installed software via uninstall information, suggesting additional victim profiling prior to theft or follow-on actions.
Amber Albatross has been tracked as a prevalent threat cluster and is notable for blending adware- or PUP-linked distribution with malware-style staging, obfuscation, and reconnaissance. Its behavior is consistent with an infostealer-oriented operation targeting Windows endpoints through deceptive software installation workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage activity cluster delivered via fake software installers that ultimately deploys a PyInstaller executable with stealer functionality.
A malware family delivered via masquerading installers/PUP-like software that culminates in a PyInstaller payload protected by Pyarmor. The final payload performs host and browser reconnaissance, checks for hypervisors, antivirus/firewall products, installed software, and attempts to access browser profiles or user data folders, exhibiting behavior typical of a stealer.
Cluster of activity involving staged installers leading to a PyInstaller EXE with stealer capabilities.
The other threats on our top 10 list for July are no strangers to the list, including Amber Albatross, which dropped to 2nd.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.