ArdaMax
- Malware type
- keylogger, screen-capture, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-18 06:25:53
- Profile updated
- 2026-07-07 13:47:43
Context
According to f-secure, Ardamax is a commercial keylogger program that can be installed onto the system from the product's website.& When run, the program can capture a range of user activities, such as keystrokes typed, instant messenger chat logs, web browser activity and even screenshots of the active desktop. This program can be configured to a complete stealth mode, with password protection, to avoid user detection. The information gathered is stored in an encrypted log file, which is only viewable using the built-in Log Viewer. The log file can be sent to an external party through e-mail, via a local area network (LAN) or by upload to an FTP server (in either HTML or encrypted format).
Reports & references
- intezer.com — Intezer 2020 Go Malware Round Up (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ardamax (report)
- medium.com — Dissecting Ardamax Keylogger F33F922D2576 (report)
- trainsec.net — Dissecting Ardamax Keylogger (report)