Amadey is a Windows malware family first observed in 2018 and widely used as a malware-as-a-service loader in commodity cybercrime operations. It is commonly employed to establish initial access on compromised systems and deliver follow-on payloads, including infostealers, remote access trojans, cryptominers, and ransomware. Amadey has repeatedly appeared in multi-stage criminal infection chains alongside families such as StealC, RedLine, Raccoon Stealer, SmokeLoader, and SocGholish, and has been used in broader pay-per-install ecosystems.
The malware is associated with bot-style management infrastructure and loader panels that allow operators to distribute additional malware to infected hosts. Reported behavior includes persistence through Windows Registry modification, checks for installed antivirus or other security products, and use of RC4 in at least some samples. Amadey’s role in attack chains is primarily to compromise devices, maintain footholds, and stage secondary payloads rather than to specialize in data theft itself.
Observed delivery vectors include phishing attachments, malvertising, drive-by downloads, and cracked-software or keygen lures. Amadey has also been referenced in activity linked to Kimsuky-related tooling, though its predominant use is in financially motivated cybercrime rather than exclusively state-directed operations. In 2026, international law enforcement and industry partners disrupted infrastructure shared by Amadey and StealC during Operation Endgame, reflecting the malware’s continued operational relevance and its integration into larger criminal service ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Amadey (loader/bot)
Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. ... SocGholish and Amadey function as loaders for introducing next-stage malware ... A C++-based modular backdoor, it's known to be active since October 2018 and advertised by a threat actor known as InCrease.
References https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
24 distinct techniques documented for this family, organized by ATT&CK tactic.
De buitgemaakte gegevens kunnen door criminelen gebruikt worden om zich voor te doen als het slachtoffer en er zodoende geld van te stelen, of om toegang te verkrijgen tot (bedrijfs)netwerken en daar meer slachtoffers te maken.
The campaign also uses gaming-themed content and automated outreach to draw people toward its malware delivery ecosystem.
T1106 Native API Amadey utilizes various Windows API functions throughout its execution.
De buitgemaakte gegevens kunnen door criminelen gebruikt worden om zich voor te doen als het slachtoffer en er zodoende geld van te stelen, of om toegang te verkrijgen tot (bedrijfs)netwerken en daar meer slachtoffers te maken.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Malware authors rely on them to hide sensitive parts of their operations, whether it’s encrypting configuration, shellcode, concealing command-and-control (C2) traffic, or simply obfuscating strings to hinder analysis.
De buitgemaakte gegevens kunnen door criminelen gebruikt worden om zich voor te doen als het slachtoffer en er zodoende geld van te stelen, of om toegang te verkrijgen tot (bedrijfs)netwerken en daar meer slachtoffers te maken.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
814 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
153 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware named as a target of Operation Endgame law enforcement action.
A loader component in the STANDOFF package, supported by referenced Amadey infrastructure and used to help deliver or manage additional payloads.
Loader mentioned as being bundled alongside Stealc in cybercrime service chains.
Loader/bot malware installed alongside other payloads in the campaign bundle.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.