A reverse-engineering walkthrough showed how Ghidra can be scripted to automatically recover obfuscated strings from Amadey 1.09, replacing repetitive manual analysis with automated annotation inside the disassembler and decompiler. The script targets the malware's __Z8aDecryptPc routine, reproduces its repeating-key subtraction logic in Java, identifies references to the function through Ghidra's decompiler and P-code APIs, and then writes recovered plaintext back into the project as comments and bookmarks.
The published results indicate the workflow decrypted 47 strings, reused 11 cached values, added 210 comments, and created 47 bookmarks in about 16 seconds, illustrating how scripting can accelerate malware triage. The approach aligns with earlier Amadey string-decryption tooling built for IDA Pro/Hex-Rays, including a Python script that extracts encrypted operands, derives a key, decrypts strings, and annotates disassembly, showing that analysts are increasingly codifying Amadey deobfuscation across multiple reverse-engineering platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A public GitHub repository shows the file "Amadey/amadey_string_decryptor.py" with the latest commit labeled "update." The repository view dates that commit to Aug. 24, 2023.
The article notes the walkthrough used a Ghidra build from December 21, 2020, described as slightly ahead of Ghidra 9.2.1.
The analyzed article states that the U.S. National Security Agency released Ghidra as a free and open-source reverse engineering tool on March 21, 2019.
The Max Kersten article says the Amadey sample it analyzes was the unpacked stage originally referenced from a KrabsOnSecurity blog post in February 2019.
Max Kersten published a technical walkthrough showing how to build a Ghidra Java script to automatically decrypt and annotate encrypted strings in an Amadey 1.09 sample. The completed script reportedly decrypted 47 strings, reused 11 cached results, placed 210 comments, and created 47 bookmarks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
maxkersten.nl
Open sourcegithub.com
Open sourceghidra-sre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.