Ammyy Admin is a legitimate Windows remote administration and remote desktop tool that has been repeatedly abused by threat actors as a remote access trojan for unauthorized access. In malicious operations, it has been delivered through spearphishing and malspam campaigns using archive attachments, macro-enabled Microsoft Word documents, and downloader scripts. Observed infection chains include documents that require users to enable macros, after which script-based downloaders retrieve and install Ammyy Admin on victim systems. It has also appeared in campaigns targeting exposed MS-SQL servers for remote access following compromise.
As used by attackers, Ammyy Admin provides persistent remote control of infected hosts and supports post-compromise activity across enterprise environments. Reported intrusions involving Ammyy Admin included long dwell times, movement toward domain administrator and server access, and likely data theft prior to follow-on actions such as ransomware deployment. Victims in documented campaigns included medium-to-large companies, including Japanese enterprises, and related activity has also been associated with broader criminal operations.
A closely related malware family, FlawedAmmyy, is derived from leaked source code for version 3 of Ammyy Admin and has been used in both highly targeted email attacks and very large spam campaigns associated with TA505. FlawedAmmyy retains remote desktop control and adds RAT-style functionality including file system management, proxy support, and audio chat. Campaigns delivering FlawedAmmyy have targeted sectors including automotive and relied on either macro-enabled documents or multi-stage delivery chains involving shortcut files, JavaScript, and Quant Loader. Together, these cases establish Ammyy Admin and its derivatives as notable examples of legitimate remote administration software repurposed for intrusion, persistence, and post-exploitation on Windows networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
it was discovered that the infected computers had also been previously targeted by a spear phishing campaign that installs a RAT, or Remote Access Trojan, on the victim's computer. These phishing emails pretend to be receipts that contain a zip attachment with a malicious Word document inside it.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ammyy Admin is a remote access tool that can be abused by attackers to gain persistent access to compromised systems.
Legitimate remote desktop/administration software (v3 source leaked) whose codebase was repurposed into the FlawedAmmyy RAT.
Ammyy Admin is a legitimate remote administration tool abused here as a RAT to gain full access to victim systems following spear-phishing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.