ArdaMax

Malware type
keylogger, screen-capture, spyware
Family
Malware family
Last IoC activity
2026-07-18 06:25:53
Profile updated
2026-07-07 13:47:43

Context

According to f-secure, Ardamax is a commercial keylogger program that can be installed onto the system from the product's website.& When run, the program can capture a range of user activities, such as keystrokes typed, instant messenger chat logs, web browser activity and even screenshots of the active desktop. This program can be configured to a complete stealth mode, with password protection, to avoid user detection. The information gathered is stored in an encrypted log file, which is only viewable using the built-in Log Viewer. The log file can be sent to an external party through e-mail, via a local area network (LAN) or by upload to an FTP server (in either HTML or encrypted format).

Reports & references

  • intezer.com — Intezer 2020 Go Malware Round Up (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ardamax (report)
  • medium.com — Dissecting Ardamax Keylogger F33F922D2576 (report)
  • trainsec.net — Dissecting Ardamax Keylogger (report)

External references