Amadey Loader is a Windows malware loader used to deliver additional payloads in criminal intrusion campaigns. It has been observed in mass-distribution activity and as part of exploit-kit-driven infections, including delivery chains involving RIG exploit kit. Amadey Loader functions primarily as a staging mechanism for follow-on malware and has been associated with campaigns that delivered families such as SystemBC, DarkGate, Matanbuchus, NetSupport, XMRig, clipboard hijackers, and Lumma Stealer. Its role in these operations is to establish execution on the victim host and retrieve or install secondary malware selected by the operator.
Operationally, Amadey Loader is used by multiple threat actors rather than being exclusive to a single group. Reporting has noted overlap between activity involving Smokeloader, Amadey Loader, AveMaria, and ServHelper, with some related campaigns assessed as possibly linked to TA505, although exclusive attribution of Amadey itself to that actor is not supportable from the available facts. The malware’s repeated appearance across unrelated campaigns indicates it is a broadly adopted crimeware component in the malware-delivery ecosystem.
Amadey Loader targets Windows systems and is notable for its use as an intermediary payload in larger infection chains. In observed cases it has been distributed through exploit-kit activity and then used to fetch additional malware, making it a flexible initial-stage or mid-stage loader in financially motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Amadey Loader is a malware loader used to deliver additional malicious payloads to infected systems.
Loader used to distribute SystemBC (and associated tasks/URLs) in the observed July 2019 RIG exploit-kit campaign.
A malware loader referenced as part of prior campaigns linked to the same actor associated with the new SmokeLoader variant.
Downloader/loader used as an eCrime enabler for payload delivery across multiple actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.