Researchers reported that Amadey has evolved from an information-stealing bot into a broader malware delivery platform, with newer variants adding screenshot capture, expanded credential theft, clipboard hijacking, and delivery of follow-on payloads such as Remcos RAT, RedLine Stealer, and LockBit 3.0. Recent analyses said the malware is being distributed through multiple channels including the RIG Exploit Kit, phishing emails, fake software installers, torrent-distributed cracks and keygens, malicious Office documents, and gaming cheat sites. Once executed, Amadey typically profiles the host, checks for security products, establishes persistence through registry changes, scheduled tasks, or startup-folder abuse, and communicates with command-and-control servers over plain HTTP to fetch plugins and additional malware.
Multiple reports said Amadey operators are using modular DLL components such as cred.dll, scr.dll, clip64.dll, and newer credential-stealing plugins to harvest browser, remote access, FTP, Outlook, and MikroTik data while also capturing screenshots and replacing cryptocurrency wallet addresses in the clipboard. Long-term infrastructure tracking found hundreds of active Amadey C2 servers and thousands of secondary payloads, showing that the malware has become a durable loader-as-a-service platform with ties to overlapping criminal campaigns. Analysts also observed delivery chains involving SmokeLoader and Nitol, abuse of public-interest lures such as fake KakaoTalk updates, and continued use of Amadey to stage ransomware and remote-access infections on compromised Windows systems.

Pull IOCs and campaign context straight into your stack.
25 events from the most recent confirmed update back to the earliest known activity.
The same Zscaler analysis found the latest Amadey variant using its C2 tasking to push Remcos RAT, alongside other payloads including DoublePulsar and EternalBlue-related components.
Zscaler analyzed a newer Amadey version delivered through the RIG Exploit Kit that added screen-capturing functionality, updated DLL plugins, and credential theft from multiple remote access and file transfer applications.
The long-term infrastructure study confirmed Amadey version 4.x in November 2023 and noted that active C2 counts dropped that month because of the version 4 changes.
Splunk's threat analysis described Amadey's persistence, anti-sandbox checks, plugin use, and C2 behavior, and noted a campaign in which it delivered LockBit ransomware through PowerShell code.
An April 2023 reverse-engineering write-up concluded that a malware sample initially believed to be RedLine Stealer was actually Amadey Bot after unpacking and decoding its strings and configuration.
The JPCERT/JSAC study found that the number of additional payloads delivered through Amadey increased dramatically in 2023, with roughly 100 malware families observed overall.
Cyble researchers found Amadey being actively used against gamers through fraudulent Valorant cheat websites. Victims downloaded a RAR archive containing Seil.exe, which installed Amadey and enabled credential theft, clipboard hijacking, and further malware delivery.
ASEC reported an active campaign in which Nitol DDoS malware, distributed as fake software cracks and keygens, downloaded and installed Amadey. After connecting to C2, Amadey stole credentials, captured screenshots, and downloaded more malware.
VMRay reported increased activity involving Amadey beginning in November 2022 and analyzed version 3.83 using newer string encoding, scheduled-task persistence, and clipboard-hijacking via clip64.dll.
The long-term infrastructure study found that the number of active Amadey C2 servers increased from November 2022, indicating a notable expansion in operations.
ASEC documented a campaign using malicious Word documents and disguised executables to install Amadey, which then contacted its C2 and downloaded LockBit payloads in PowerShell and EXE form for execution.
ASEC reported that an executable disguised as a Word document, Resume.exe, associated with an Amadey-to-LockBit infection chain was collected on October 27, 2022.
ASEC analyzed a campaign using email-delivered fake KakaoTalk update files themed around the Kakao service outage. The malware downloaded srms.dat, which dropped and launched Amadey as tapi32.dll and sent host information to its C2.
The JPCERT/JSAC study concluded that Amadey became a major threat from October 2022 onward, with variant counts increasing dramatically from that month.
ASEC reported an infection chain in which SmokeLoader installed Amadey, which then persisted via registry and scheduled task changes, captured screenshots, downloaded cred.dll, and fetched RedLine Stealer from attacker infrastructure.
VMRay noted that OALabs developed a decoding routine for Amadey's newer string-encoding algorithm in late 2022, helping analysts decode recent variants.
ASEC said LockBit 3.0 campaigns delivered through Amadey had been observed in Korea since 2022, showing Amadey's use as a ransomware loader against corporate targets.
The long-term C2 study found that Amadey operators started actively distributing additional payloads from late 2021 onward, reflecting its evolution into a broader malware delivery platform.
A 2021 write-up documented an updated Amadey cred plugin that added harvesting of MikroTik Winbox data and Outlook profile data from the Windows registry.
The JPCERT/JSAC study states that screenshot-capturing plug-in capability was observed from around May 2020, marking an expansion beyond basic infostealing behavior.
On February 27, 2020, researchers probing Amadey infrastructure found three URLs referencing the NSA, FBI, and CIA, which they assessed may have resulted from improper configuration.
A long-term infrastructure study found one Amadey campaign that spread the AVG installer without observed malicious payloads from that C2 server during the period from late October to late November 2019.
A 2019 analysis described an infection chain in which a malicious Excel file launched msiexec.exe to install Amadey from a remote URL. The sample dropped itself under ProgramData, modified the User Shell Folders Startup registry value for persistence, and beaconed to its C2 over HTTP POST.
Multiple references state that Amadey first emerged in 2018 as a Russian-origin malware family and bot/downloader used to steal information and deliver additional payloads.
KISA published a security notice on October 17, 2022 warning that attackers were exploiting concern over the Kakao service malfunction issue to distribute malware disguised as KakaoTalk installers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 82 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
16 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourcezscaler.com
Open sourcevmray.com
Open sourcesplunk.com
Open sourcemedium.com
Open sourcenao-sec.org
Open sourcejsac.jpcert.or.jp
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.