Amadey

MITRE ATT&CK: S1025 View on attack.mitre.org

Aliases: Amadey

First seen
2018-10-01 00:00:00
Malware type
botnet, trojan, downloader
Family
Malware family
Operating systems
windows
Related IoCs
3377 (2818 malicious)
Last IoC activity
2026-09-02 02:54:57
Profile updated
2026-07-07 12:54:46

Context

Amadey is a Trojan bot that has been used since at least October 2018.

Recent IoC activity

2,822 malicious indicators in Maltiverse are attributed to Amadey (S1025). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname svclsc.com 2026-09-03 2
file sample c7b6b83c40c52e87c031b9e8cbabdb3e.exe 2026-09-03 2
hostname windowsedgeupdater.com 2026-09-03 1
hostname garts.at 2026-09-03 1
hostname myrtler.biz 2026-09-03 2
hostname rebustan.top 2026-09-02 1
URL http://196.251.107.186/qK3mRv9L/ 2026-09-02 1
IP address 196.251.107.186 2026-09-02 4
hostname mi.overlapsnowbound.com 2026-09-02 2
IP address 91.92.242.236 2026-09-02 4
hostname mi.limpingbronco.com 2026-09-02 2
hostname spasopro.at 2026-09-02 3
URL http://spasopro.at/Lsge63sd3/index.php 2026-09-02 2
hostname 900ama.com 2026-09-02 2
file sample 83f5e08f80cb28ba3197e06721b05fc1a1018cb7ea908f054aea6a69014e1a13 2026-09-02 2
file sample 83f17052a7366bd07cacf01d9a6fcc31b6bcb5b89fc7f5320edbfa2de3c01b85 2026-09-02 2
hostname telemety-sys.lol 2026-09-02 1
hostname msupgrade.top 2026-09-02 2
hostname actualisation-service.com 2026-09-02 1
hostname app-figma.com 2026-09-02 1

Detection coverage

  • 10 YARA rules
  • 440 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Fast Flux DNS (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Data from Local System (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Mark-of-the-Web Bypass (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Used by threat actors

  • TA505 (threat-actor)
  • Kimsuky (threat-actor)
  • Emmenhtal Loader Distribution Activity (campaign)

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_PWS_Amady (yara-rule)
  • DITEKSHEN_INDICATOR_TOOL_SCR_Amady (yara-rule)
  • DITEKSHEN_INDICATOR_KB_ID_Amadey (yara-rule)
  • DITEKSHEN_INDICATOR_KB_ID_UNK01 (yara-rule)
  • SEKOIA_Loader_Amadey_Standalone_May23 (yara-rule)
  • SEKOIA_Loader_Amadey_Stealer_Plugin (yara-rule)
  • SEKOIA_Loader_Amadey_Clipper_Plugin (yara-rule)
  • SIGNATURE_BASE_MAL_Win_Amadey_Jun25 (yara-rule)
  • CAPE_Amadey (yara-rule)
  • MALPEDIA_Win_Amadey_Auto (yara-rule)

Reports & references

  • telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
  • CrowdStrike — Report2021Gtr (report)
  • Microsoft — Frequent Freeloader Part Ii Russian Actor Secret Blizzard Using Tools Of Other Groups To Attack Ukraine (report)
  • fsec.or.kr — 1382.Do (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • trellix.com — Conti Leaks Examining The Panama Papers Of Ransomware (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
  • fsec.or.kr — 2297.Do (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • asec.ahnlab.com — 59590 (report)
  • rapid7.com — Fake Update Utilizes New Idat Loader To Execute Stealc And Lumma Infostealers (report)
  • cocomelonc.github.io — Malware Pers 1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Amadey (report)
  • team-cymru.com — Seychelles Seychelles On The C 2 Shore (report)
  • thecyberexpress.com — Amadey Botnet Back Via Phishing Sites (report)
  • linkedin.com — Idan Tarab 7A9057200 Apt Ttps Coralraider Activity 7238998746254999553 57Lg (report)
  • cybereason.com — The Hole In The Bucket Attackers Abuse Bitbucket To Deliver An Arsenal Of Malware (report)
  • embeeresearch.io — Shodan Censys Queries (report)
  • research.checkpoint.com — Chain Reaction Rokrats Missing Link (report)
  • nao-sec.org — Analyzing Amadey (report)
  • zscaler.com — Latest Version Amadey Introduces Screen Capturing And Pushes Remcos Rat (report)
  • asec.ahnlab.com — 41450 (report)
  • blog.minerva-labs.com — Underminer Exploit Kit The More You Check The More Evasive You Become (report)
  • blogs.blackberry.com — Threat Spotlight Amadey Bot (report)

External references