Breakglass Intelligence reported that an Amadey botnet campaign tracked as fbf543 functioned as a large pay-per-install service rather than a single malware run, linking more than 100 samples across 24 malware families over roughly 10 days. The operation used sys32[.]cc as a Cloudflare-fronted Amadey C2 while backend and payload hosting were tied to labinstalls[.]info at 158.94.211.222, with additional delivery infrastructure including qpgroup[.]top and bulletproof hosting providers such as Omegatech, 1337 Services, and Podaon SIA. Researchers said the service likely served multiple criminal customers and assessed it as a financially motivated mid-tier cybercrime operation with likely ties to the CIS criminal ecosystem.
The campaign delivered a broad mix of malware including Vidar, LummaStealer, QuasarRAT, XWorm, SmokeLoader, Mirai, and ScreenConnect, with Vidar appearing most often in 29 samples across two distinct lineages. Delivery methods included a Delphi PE wrapped in Inno Setup, confirmed version.dll sideloading, an HTA dropper abusing mshta.exe and curl.exe to fetch payloads from 188.137.224.92, a fake Roblox executor using a modified VMware Tools binary, LimeWire-hosted payloads, and ConnectWise RMM MSI packages signed with legitimate certificates. The report said the operators mixed evasive tradecraft such as anti-VM checks, ping delays, XOR-encoded dead-drop resolvers, Cyrillic homoglyphs, and stolen or abused code-signing certificates with operational mistakes including a self-descriptive backend domain and predictable payload URL patterns.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Breakglass Intelligence published its findings, describing the campaign's loader behavior, confirmed version.dll sideloading, Cloudflare-fronted C2, bulletproof-hosted backend infrastructure, and varied delivery methods such as HTA droppers, fake Roblox executors, LimeWire-hosted payloads, and signed RMM installers. The report assessed the operator as a financially motivated mid-tier cybercrime service likely tied to the CIS criminal ecosystem.
Breakglass Intelligence determined that over roughly 10 days the Amadey operation delivered more than 100 samples across 24 malware families, including Vidar, LummaStealer, QuasarRAT, XWorm, ScreenConnect, SmokeLoader, and Mirai. The breadth of payloads indicated multiple criminal customers using the same distribution service.
By March 2026, the Amadey-tagged "fbf543" operation was actively distributing malware through infrastructure including sys32[.]cc, labinstalls[.]info, and qpgroup[.]top. The campaign functioned as a pay-per-install service rather than a single-family malware run.
A MalwareBazaar sample later used as the starting point for Breakglass Intelligence's investigation into the Amadey "fbf543" campaign was submitted by Bitsight. This sample became the anchor for linking a broader distribution operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 54 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.