Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
5 malware families

Amadey

Also known asamadey

Amadey is a modular malware loader/botnet sold as a malware-as-a-service offering and advertised on darknet forums by the account InCrease since October 2018. Its primary purpose is to distribute additional malware to compromised systems, and reported modules also include clipboard monitoring, credential theft, VNC-based remote access, and later hVNC, MSI silent installer support, RDP enabling, SYSTEM-level cmd.exe execution, and support for encrypted payloads. ESET reported that Amadey operates under a pay-per-rebuild model in which affiliates buy a license and pay for each new build, and that affiliates run their own self-hosted administration panels and infrastructure rather than relying on centrally managed C2, resulting in a fragmented ecosystem. ESET identified 53 unique Amadey clusters and noted that one cluster accounted for nearly 34% of processed Amadey samples and appeared to operate a pay-per-install model, often delivering multiple Lumma Stealer samples from different affiliates to the same victim. Amadey has been tracked globally, with detections reported especially in India, Turkey, Egypt, Mexico, and Spain. Delivery methods observed in telemetry include fake software updates, cracked software installers, and third-party malware loaders. Technically, Amadey samples contain at least one hardcoded C&C URL, support up to three entries, embed an RC4 key used for C&C encryption, and include an sd value transmitted during the initial handshake that likely represents a build identifier. It communicates over HTTP POST in a three-stage lifecycle of initial beacon, registration, and tasking. ESET reported a complete codebase rewrite in August 2020 with version 1.99.5, and version 5.03 released in October 2024. Recent reporting tied Amadey to campaign fbf543, an active botnet operation that distributed more than 100 samples across 23 malware families in 10 days and over 50 payloads in four days. In that campaign, Amadey deployed legitimate, signed remote management and monitoring tools from ConnectWise, DattoRMM, Atera, GoToResolve, and N-able as persistent backdoors by abusing normal vendor provisioning workflows and pre-configuring installers to connect to attacker-controlled relay infrastructure. The same campaign also delivered malware including Vidar, StealC, LummaStealer, Rhadamanthys, RemcosRAT, ValleyRAT, XWorm, QuasarRAT, AsyncRAT, DarkVisionRAT, SmokeLoader, SantaStealer, RustyStealer, SalatStealer, Fuery, and a VOLK/XMRig-based cryptominer. Breakglass Intelligence assessed the fbf543 operator profile as consistent with an Initial Access Broker or ransomware affiliate playbook. Amadey was also one of the malware families targeted in Operation Endgame, a coordinated disruption effort involving Microsoft Digital Crimes Unit, ESET, BitSight, Lumen, Mitsui Bussan Secure Directions, and law enforcement partners. The operation targeted all known affiliate-operated infrastructure for Amadey and Stealc and affected about 50 domains and nearly 200 active IP-based command-and-control servers.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇮🇳 India
  • 🇹🇷 Türkiye
  • 🇪🇬 Egypt
  • 🇲🇽 Mexico
  • 🇪🇸 Spain
MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics8 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
TA0001
Initial Access
1 technique
T1566
Phishing
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1555
Credentials from Password Stores
TA0009
Collection
1 technique
T1056
Input Capture
TA0011
Command and Control
1 technique
T1105
Ingress Tool Transfer
TA0040
Impact
1 technique
T1496
Resource Hijacking
ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

eset welivesecurity blogNews
Jun 24, 2026
ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Malware-as-a-service loader ecosystem whose affiliates operate their own C2 infrastructure and use it to distribute additional malware, exfiltrate data, and enable remote access. The report discusses disruption of Amadey infrastructure and clustering of affiliate-operated botnets.

Read more
breakglass intelNews
Mar 12, 2026
Amadey Botnet Campaign "fbf543" Weaponizes 9 Legitimate RMM Tools Across 5 Vendors for EDR-Evasive Persistence - Breakglass Intelligence - Breakglass Intelligence

Conducting a multi-stage botnet campaign that delivers stealers, RATs, and legitimate RMM tools for persistent access, with likely monetization through access sales, ransomware affiliate activity, or cryptomining.

Read more
breakglass intelNews
Mar 9, 2026
The Sentinel Variant: evilgrou-tech Deploys HVNC-Equipped QuasarRAT for Crypto Targeting While PFCLOUD Nexus Links Three Malware Operations to One Bulletproof /24 - Breakglass Intelligence - Breakglass Intelligence

Botnet/BaaS staging operation distributing numerous commodity malware families for multiple customers through a shared upstream provider also linked to evilgrou-tech infrastructure.

Read more
breakglass intelNews
Mar 5, 2026
Fuery: A Go-Based Implant Hiding Behind Raft Consensus and a $117 Monero Operation - Breakglass Intelligence - Breakglass Intelligence

Modular Windows botnet used as malware-as-a-service to deliver Fuery and VOLK CryptoMiner in campaign fbf543.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.