Amadey is a modular Windows malware loader and Trojan bot first observed around October 2018. It collects information about compromised hosts, communicates with command-and-control servers, and downloads and executes additional malicious payloads. Distributed within the cybercrime malware-as-a-service and pay-per-install ecosystem, it serves as an initial-access platform for information stealers, remote-access Trojans, and ransomware. Its use has been linked to TA505 and LockBit-associated operators. Delivered payloads include StealC, VectraRAT, and SeroRAT.
Amadey profiles operating-system versions, system architecture, computer and user names, domain membership, administrative status, and installed antivirus products. Its plugin ecosystem supports browser and application credential collection, cryptocurrency-wallet credential collection, screenshot capture, clipboard monitoring, and proxying. Analyzed variants establish persistence through scheduled tasks and changes to the Windows Startup-folder configuration, request elevated execution, and modify filesystem permissions to impede removal. Runtime string decoding and third-party packing help conceal malicious functionality. Observed command-and-control implementations include HTTP POST check-ins and, in newer versions, RC4-encrypted data represented as hexadecimal strings.
Infection vectors include phishing emails, bundling with pirated software, and exploit-based delivery. Campaigns exploiting self-hosted GitLab instances through CVE-2023-7028 have used Amadey to distribute StealC. Secondary payloads may be hosted on legitimate services such as Discord, Bitbucket, and GitHub. Amadey and StealC infrastructure was targeted by a Microsoft-led disruption operation supported by law enforcement and private-sector partners in June 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploitation de CVE-2023-7028 (GitLab) pour distribuer StealC via le loader Amadey. | « Exploitation de CVE-2023-7028 (GitLab) pour distribuer StealC via le loader Amadey. »
We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine. | One such threat we've kept an eye on is Amadey, a bot of Russian origin, which was first seen in late 2018. Once on a victim's machine, Amadey sends user data to a Command and Control (C&C) server and executes other tasks sent back by the C&C server.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Amadey is a modular Trojan bot and malicious loader first identified in late 2018, targeting Windows operating systems. The analyzed sample communicates its Amadey version (3.50) and ID to C2 infrastructure.
TA406 has used many different malware families, including KONNI, SANNY, CARROTBAT/CARROTBALL, BabyShark, Amadey and Android Moez.
The Amadey bot is a Trojan that was first discovered in 2018 and is used to steal sensitive information from the infected device.
During our analysis of the ROKRAT infection chain, we came across a similar chain leading to the deployment of Amadey, a commercial RAT sold in underground forums.
During our analysis of the ROKRAT infection chain, we came across a similar chain leading to the deployment of Amadey, a commercial RAT sold in underground forums.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Amadey (loader/bot)
26 distinct techniques documented for this family, organized by ATT&CK tactic.
RegOpenKeyExA and RegQueryValueExA APIs are used to obtain the Windows Build number; the computer name is also retrieved through the registry.
The ComputerNameDnsDomain parameter of the GetComputerNameExW API is used to retrieve the system's DNS domain name.
The sample retrieves OS version, Windows build number, native system architecture, CPU details, and computer name.
The report's MITRE ATT&CK mapping lists Virtualization/Sandbox Evasion (T1497).
The HttpSendRequestA API initiates requests to the "jg94cVd30f/index.php" endpoint... The sample sends the previously collected system information to the server through a POST request.
1,128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader utilisé pour distribuer le stealer StealC dans la chaîne décrite.
Loader used to deploy the StealC infostealer in campaigns targeting vulnerable self-hosted GitLab instances.
Microsoft had previously dismantled cybercrime-as-a-service infrastructure belonging to gangs distributing SocGholish, Amadey and StealC malware.
The content identifies Amadey as the delivery/dropper associated with several SeroRAT samples.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.