FlawedAmmyy is a Windows remote access trojan derived from leaked source code of the legitimate Ammyy Admin remote-administration tool and first observed in 2016. It is a full-featured RAT used in financially motivated intrusion activity, most notably by TA505, and has also been observed in delivery chains involving Necurs, Amadey, and AndroMut. It has been associated with enterprise intrusions that later led to Clop ransomware deployment, including operations targeting financial institutions, government entities, and other organizations across multiple regions.
The malware supports broad post-compromise control and collection functions. Reported capabilities include command execution through PowerShell and the Windows command shell, file upload and download, screenshot capture, clipboard collection, keylogging, mouse-event collection, host reconnaissance, and exfiltration over its command-and-control channel. During initial execution it can enumerate the current user, privilege level, operating system, computer name, and installed antivirus products, including via Windows Management Instrumentation, and it can check for smart-card presence. FlawedAmmyy has used HTTP for command and control and has been observed using SEAL encryption and handshake obfuscation during initial communications.
Persistence has been established through the Windows Run key, and execution has been observed via common Windows utilities including msiexec and rundll32. The malware has also been reported deleting files through batch-script execution as part of cleanup or defense-evasion behavior. In some campaigns, FlawedAmmyy was delivered through phishing-driven infection chains using malicious Office documents, HTML or ISO lures, macro-enabled files, MSI installers, and intermediate downloaders. TA505 notably used it as a second-stage payload in campaigns that evolved from broad email distribution into hands-on intrusions with lateral movement and eventual ransomware deployment.
FlawedAmmyy is widely regarded as one of the characteristic TA505 backdoors of the late 2010s and an important component in the group’s transition from mass-malspam operations to more targeted enterprise compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...or less widely distributed malware like FlawedAmmyy at scale following similar tests.
Finding Grace as a payload is interesting, as it is known to be almost exclusively used by TA505, which further strengthens previous claims of a connection between Silence Group and TA505 made by Group-IB, which was based on source code comparison with FlawedAmmyy.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 seems to have distributed its malware only through phishing email campaigns... The only infection vector currently known to be used by the TA505 intrusion set is phishing emails including a malicious attachment or link.
The HTM or HTML attachments contained links to the download of an Office file. Depending on the specific case, the delivered Word or Excel file used macros to execute a Msiexec command that would download and execute either the FlawedAmmyy loader or AndroMut.
FlawedAmmyy has used cmd to execute commands on a compromised host.
문서 파일에 삽입된 매크로를 통해 원격제어 악성코드 다운로더 실행... 문서 파일에 삽입된 매크로 코드는 VBA와 XLM 형태가 확인되었다. | 문서 파일에 삽입된 매크로 코드는 VBA와 XLM 형태가 확인되었다.
This intrusion set relies exclusively over that period on social engineering to run its payload contained in malicious attachments linked to emails sent... The victim is then encouraged to download, open and enable VBA macros of an Office document.
Le but de ces documents était souvent d’exécuter via des macros des commandes msiexec sur la machine de la victime pour télécharger et exécuter un code malveillant. | Ce mode opératoire s’appuie exclusivement durant cette période sur de l’ingénierie sociale pour faire exécuter ses charges contenues dans des pièces jointes malveillantes... La victime est alors incitée à télécharger, ouvrir et activer les macros VBA d’un document Office.
Second stage executables may also be encrypted, requiring the analyst to gather an understanding of how this code is manipulated.
Malware authors commonly utilize packers (Roccia, 2017) as a method of concealing functionality and characteristics of their malicious code, making an analyst's job more difficult.
runmemxor : Download XOR encrypted .DLL and decrypt and run
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The Necurs modules check if the machines have files that contain any of the following strings that exist under “%APPDATA%” such as: WALLET.DAT BITCOIN-QT ELECTRUM
FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
In the cases that involved AndroMut, Proofpoint researchers observed it downloading FlawedAmmyy... 300 - Base64 decodes the “data” value, saves it the %TEMP% directory using the “name” value, then executes it with the CreateProcessW Windows API.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
63 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan discussed in the context of unpacking and decrypting a sample within a debugger to understand its concealed functionality and capabilities.
Remote access trojan used in Clop intrusions to gather information and download additional malware components.
FlawedAmmyy is a remote access trojan (RAT) used by threat actors for persistent access and control over compromised systems.
Referenced only as background supporting attribution links between Silence Group and TA505.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.