Researchers tied ResolverRAT, LummaStealer, and an Amadey botnet cluster to an active financially motivated campaign that has operated since at least late 2025 and uses fake browser update lures, staged loaders, and legitimate remote management tools for persistence. One analyzed chain used a Donut-decrypted, triple-protected .NET loader to deliver both ResolverRAT and LummaStealer at once, combining persistent remote access with credential and cryptocurrency wallet theft. The malware used layered obfuscation including .NET Reactor, custom transformations, AES-256-CBC, GZip, process hollowing, fragmented WinAPI reconstruction, forged compile timestamps, encrypted resource blobs, and certificate pinning, while operators rotated infrastructure across dozens of IPs, multiple domains, and hosting providers in Russia, the Netherlands, Germany, Poland, and elsewhere. Investigators also identified a fake Microsoft-themed domain, pat[.]microsoft-telemetry[.]at, and newly activated infrastructure such as kampf[.]huehnchenfarm[.]ru tied to the same ecosystem.
A parallel March 2026 investigation linked the fbf543 Amadey campaign to more than 50 payloads spanning at least 13 malware families, including Vidar, QuasarRAT, XWorm, AsyncRAT, Smoke Loader, and LummaStealer, with delivery through fake installers and hosting on infrastructure centered on Omegatech LTD (AS202412) and related abusive networks. Analysts found that the operators also abused nine legitimate, signed RMM tools from ConnectWise, DattoRMM, Atera, GoToResolve, and N-able, configuring them to beacon to attacker-controlled relays rather than compromising the vendors themselves. A separate Go-based loader unpacked LummaStealer with AES, RC4, and QuickLZ before hollowing AppLaunch.exe, reinforcing a playbook built around stealthy loaders, infostealer deployment, redundant access channels, and monetization consistent with an initial access broker or ransomware affiliate operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On March 12, 2026, Breakglass Intelligence published multiple reports detailing the ResolverRAT/Lumma dual-payload loader, the broader ResolverRAT infrastructure, and the Amadey fbf543 malware distribution and RMM abuse campaign. The reports connected active infrastructure, malware samples, and hosting patterns across the operations.
A new Google WE1 certificate for huehnchenfarm[.]ru was issued on March 10, 2026. This supported the assessment that the ResolverRAT-associated infrastructure was being actively maintained and refreshed.
Breakglass observed new infrastructure for the ResolverRAT-linked operation on March 9, 2026, including kampf[.]huehnchenfarm[.]ru and IP address 45[.]141[.]119[.]34. The finding showed the campaign was still actively evolving during the investigation.
Researchers linked nine legitimate but attacker-configured RMM installers uploaded to MalwareBazaar on March 9, 2026 to the fbf543 campaign. The tools came from ConnectWise, DattoRMM, Atera, GoToResolve, and N-able and were used for stealthy persistence.
The Amadey botnet campaign tagged fbf543 distributed more than 50 payloads across at least 13 malware families between March 6 and March 10, 2026. Payloads included LummaStealer, Vidar, QuasarRAT, XWorm, AsyncRAT, Smoke Loader, and multiple abused remote management tools.
A Donut-decrypted .NET executable later tied to the broader ResolverRAT cybercrime campaign was submitted to MalwareBazaar on March 5, 2026. Breakglass used this sample to analyze the malware's obfuscation, certificate pinning, and shared infrastructure.
Researchers identified five linked malware samples observed from January through March 2026 that shared the same imphash, indicating a common build pipeline and active maintenance. These samples delivered ResolverRAT and LummaStealer together through a heavily protected .NET loader.
The five Registrar.eu domains associated with the ResolverRAT ecosystem were activated in December 2025 after months of dormancy. This marked a coordinated expansion or operationalization of the campaign's infrastructure.
Breakglass assessed the broader cybercrime operation supporting ResolverRAT, PureRAT, PureHVNC, PureLogs Stealer, and likely Lumma/ZgRAT had been active since at least November 2025. The campaign used ClearFake/ClickFix fake browser update lures and a Donut-based in-memory loader to deliver obfuscated .NET malware.
Investigators found five domains later used in the ResolverRAT-linked command-and-control ecosystem were registered together through Registrar.eu in March 2025. These domains then remained dormant for roughly nine months before activation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.