FlawedAmmyy is a remote access Trojan (RAT) discovered by Proofpoint and used since at least early 2016 in both highly targeted email attacks and large-scale malspam campaigns. It is based on leaked source code from Version 3 of the Ammyy Admin remote desktop software. Reported capabilities include remote desktop control, file system management, proxy support, audio chat, screenshot capture, clipboard collection, keylogging, command execution via PowerShell, and exfiltration of collected data to command-and-control (C2) servers. During initial profiling it enumerates the current user, leverages WMI to identify installed antivirus products, and checks whether a usable smart card is inserted in a reader. FlawedAmmyy communicates with C2 over HTTP on port 443; Proofpoint reported that its initial handshake uses SEAL-encrypted data, after which the malware sends host profiling information including OS version, privilege level, username, computer name, antivirus product, smart-card presence, and malware build time. Observed delivery vectors include macro-enabled Microsoft Word and Excel attachments, ZIP archives containing .url Internet Shortcut files that retrieved JavaScript over SMB, and infection chains involving Quant Loader and Get2 as intermediate downloaders. Proofpoint associated major FlawedAmmyy distribution activity with TA505, including Japan-focused campaigns and broader mass-email operations; targeted activity included the automotive sector. Additional observed execution details include installation via msiexec.exe. Reported infrastructure and payload indicators from Proofpoint include C2 endpoints 179.60.146.3:443 and 194.165.16.11:443, SMB URL file://buyviagraoverthecounterusabb.net/documents/B123456789012.js, Quant Loader URL hxxp://wassronledorhad.in/q2/index.php, and payload URL hxxp://balzantruck.com/45rt.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Get2 was, in turn, observed downloading FlawedGrace, FlawedAmmyy, Snatch, and SDBbot (a new RAT) as secondary payloads.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
Emails contained the attachment 16.01.2018.doc which used macros to download the FlawedAmmyy RAT directly.
This JavaScript in turn downloads Quant Loader, which, in this case, fetched the FlawedAmmyy RAT as the final payload.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
avname Antivirus product name obtained via WMI query Windows Defender
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The FlawedAmmyy C&C protocol occurs over port 443 with HTTP.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FlawedAmmyy is a remote access trojan (RAT) used by threat actors for persistent access and control over compromised systems.
Remote access trojan that uses PowerShell to execute commands.
A RAT distributed as a secondary payload by Get2 and also noted as frequently distributed by TA505 in South Korea campaigns.
Remote access trojan derived from leaked Ammyy Admin v3 source code. Provides remote desktop control, file system management, proxy support, and audio chat, and is delivered via macro-enabled Office documents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.