Amadey
MITRE ATT&CK: S1025 View on attack.mitre.org
Aliases: Amadey
- First seen
- 2018-10-01 00:00:00
- Malware type
- botnet, trojan, downloader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 3377 (2818 malicious)
- Last IoC activity
- 2026-09-02 02:54:57
- Profile updated
- 2026-07-07 12:54:46
Context
Amadey is a Trojan bot that has been used since at least October 2018.
Recent IoC activity
2,822 malicious indicators in Maltiverse are attributed to Amadey (S1025). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | svclsc.com | 2026-09-03 | 2 |
| file sample | c7b6b83c40c52e87c031b9e8cbabdb3e.exe | 2026-09-03 | 2 |
| hostname | windowsedgeupdater.com | 2026-09-03 | 1 |
| hostname | garts.at | 2026-09-03 | 1 |
| hostname | myrtler.biz | 2026-09-03 | 2 |
| hostname | rebustan.top | 2026-09-02 | 1 |
| URL | http://196.251.107.186/qK3mRv9L/ | 2026-09-02 | 1 |
| IP address | 196.251.107.186 | 2026-09-02 | 4 |
| hostname | mi.overlapsnowbound.com | 2026-09-02 | 2 |
| IP address | 91.92.242.236 | 2026-09-02 | 4 |
| hostname | mi.limpingbronco.com | 2026-09-02 | 2 |
| hostname | spasopro.at | 2026-09-02 | 3 |
| URL | http://spasopro.at/Lsge63sd3/index.php | 2026-09-02 | 2 |
| hostname | 900ama.com | 2026-09-02 | 2 |
| file sample | 83f5e08f80cb28ba3197e06721b05fc1a1018cb7ea908f054aea6a69014e1a13 | 2026-09-02 | 2 |
| file sample | 83f17052a7366bd07cacf01d9a6fcc31b6bcb5b89fc7f5320edbfa2de3c01b85 | 2026-09-02 | 2 |
| hostname | telemety-sys.lol | 2026-09-02 | 1 |
| hostname | msupgrade.top | 2026-09-02 | 2 |
| hostname | actualisation-service.com | 2026-09-02 | 1 |
| hostname | app-figma.com | 2026-09-02 | 1 |
Detection coverage
- 10 YARA rules
- 440 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Fast Flux DNS (attack-pattern)
- Security Software Discovery (attack-pattern)
- Native API (attack-pattern)
- Data from Local System (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Mark-of-the-Web Bypass (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- System Location Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
Used by threat actors
Detection rules
- DITEKSHEN_INDICATOR_TOOL_PWS_Amady (yara-rule)
- DITEKSHEN_INDICATOR_TOOL_SCR_Amady (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Amadey (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_UNK01 (yara-rule)
- SEKOIA_Loader_Amadey_Standalone_May23 (yara-rule)
- SEKOIA_Loader_Amadey_Stealer_Plugin (yara-rule)
- SEKOIA_Loader_Amadey_Clipper_Plugin (yara-rule)
- SIGNATURE_BASE_MAL_Win_Amadey_Jun25 (yara-rule)
- CAPE_Amadey (yara-rule)
- MALPEDIA_Win_Amadey_Auto (yara-rule)
Reports & references
- telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
- CrowdStrike — Report2021Gtr (report)
- Microsoft — Frequent Freeloader Part Ii Russian Actor Secret Blizzard Using Tools Of Other Groups To Attack Ukraine (report)
- fsec.or.kr — 1382.Do (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- trellix.com — Conti Leaks Examining The Panama Papers Of Ransomware (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
- fsec.or.kr — 2297.Do (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- asec.ahnlab.com — 59590 (report)
- rapid7.com — Fake Update Utilizes New Idat Loader To Execute Stealc And Lumma Infostealers (report)
- cocomelonc.github.io — Malware Pers 1 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Amadey (report)
- team-cymru.com — Seychelles Seychelles On The C 2 Shore (report)
- thecyberexpress.com — Amadey Botnet Back Via Phishing Sites (report)
- linkedin.com — Idan Tarab 7A9057200 Apt Ttps Coralraider Activity 7238998746254999553 57Lg (report)
- cybereason.com — The Hole In The Bucket Attackers Abuse Bitbucket To Deliver An Arsenal Of Malware (report)
- embeeresearch.io — Shodan Censys Queries (report)
- research.checkpoint.com — Chain Reaction Rokrats Missing Link (report)
- nao-sec.org — Analyzing Amadey (report)
- zscaler.com — Latest Version Amadey Introduces Screen Capturing And Pushes Remcos Rat (report)
- asec.ahnlab.com — 41450 (report)
- blog.minerva-labs.com — Underminer Exploit Kit The More You Check The More Evasive You Become (report)
- blogs.blackberry.com — Threat Spotlight Amadey Bot (report)