Amadey is a modular malware loader and botnet offered as a malware-as-a-service operation since 2018 and commonly used to distribute additional payloads to compromised Windows systems. It has been advertised under the alias Amadey Botnet and sold through a pay-per-rebuild model in which affiliates operate their own self-hosted administration panels and command-and-control infrastructure, producing a fragmented ecosystem rather than a centrally managed service. Amadey has undergone substantial development over time, including a major codebase rewrite in 2020 and later feature additions such as hidden VNC, reverse-connect remote access, silent MSI installation support, RDP enabling, SYSTEM-level command execution, and encrypted payload support. Amadey’s primary role is initial compromise follow-on delivery and monetization. It has been observed distributing a wide range of commodity malware families, including information stealers, remote access trojans, cryptominers, and other loaders. Documented campaigns show Amadey delivering multiple payloads to the same victim, consistent with pay-per-install activity and affiliate monetization. It also supports optional modules for clipboard monitoring, credential theft, and VNC-based remote access. Operationally, Amadey communicates with command-and-control servers over HTTP POST using a staged lifecycle for beaconing, registration, and tasking, with RC4-protected communications and embedded build or cluster identifiers. Tracking has identified dozens of distinct Amadey clusters, reinforcing that affiliates typically maintain separate infrastructure. Delivery methods observed for Amadey campaigns include fake software updates, cracked software installers, and distribution by other malware loaders. Recent activity has linked Amadey to campaigns that abuse legitimate remote monitoring and management software for persistence, using vendor-signed installers configured to connect to attacker-controlled relays. Such campaigns have also deployed information stealers, RATs, cryptominers, and utilities for silent execution, aligning with initial access broker or ransomware-affiliate tradecraft. Additional Amadey-linked operations have delivered custom implants featuring reconnaissance, anti-analysis, process injection via thread hijacking, and raw-socket command-and-control, as well as cryptomining payloads. Amadey is best characterized as a financially motivated criminal malware service enabling affiliate-driven initial access, persistence, credential theft, and payload delivery at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware-as-a-service loader ecosystem whose affiliates operate their own C2 infrastructure and use it to distribute additional malware, exfiltrate data, and enable remote access. The report discusses disruption of Amadey infrastructure and clustering of affiliate-operated botnets.
Conducting a multi-stage botnet campaign that delivers stealers, RATs, and legitimate RMM tools for persistent access, with likely monetization through access sales, ransomware affiliate activity, or cryptomining.
Botnet/BaaS staging operation distributing numerous commodity malware families for multiple customers through a shared upstream provider also linked to evilgrou-tech infrastructure.
Modular Windows botnet used as malware-as-a-service to deliver Fuery and VOLK CryptoMiner in campaign fbf543.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.