Amadey is a Windows malware family and malware-as-a-service offering first publicly observed in 2018. It is most commonly used as a loader and initial-stage access component in broader criminal intrusion chains, where it establishes a foothold on compromised systems, persists, communicates with operator-controlled infrastructure, and retrieves or deploys additional payloads. Amadey has been repeatedly associated with commodity cybercrime operations and has been observed delivering follow-on malware including information stealers, remote access trojans, cryptominers, and ransomware-enabling tooling.
Operational reporting consistently places Amadey in the cybercrime supply chain as a service used to monetize infections and hand off access to other actors. It has been observed alongside families such as StealC, RedLine, Raccoon Stealer, SmokeLoader, and other commodity payloads, and has been cited as a source of stolen credentials and initial access for ransomware operators. International disruption actions under Operation Endgame targeted infrastructure used by Amadey and linked it with large-scale criminal operations affecting substantial numbers of victim systems worldwide.
Amadey supports persistence on infected hosts, including through scheduled tasks, and has been observed modifying the Windows Registry for persistence-related purposes. It also performs security-software discovery and checks for antivirus products, indicating built-in environment awareness and defense-evasion logic. Technical analysis has also identified RC4 usage in Amadey implementations. In some campaigns, Amadey has been used in front of destructive or follow-on tooling, reinforcing its role as a staging mechanism rather than a single-purpose payload.
Distribution has been tied to common commodity malware channels including phishing attachments, malvertising, drive-by downloads, and cracked-software ecosystems. Amadey has also appeared in bundled pay-per-install operations that deploy multiple malware families simultaneously. Although some reporting notes infostealer capabilities, the strongest and most consistent characterization is that Amadey primarily functions as a loader that enables secondary compromise and downstream monetization on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Amadey (loader/bot)
Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information.
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. ... SocGholish and Amadey function as loaders for introducing next-stage malware ... A C++-based modular backdoor, it's known to be active since October 2018 and advertised by a threat actor known as InCrease.
References https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers continued gaining access through internet-facing devices, remote management tools, compromised accounts, and stolen credentials. Qilin affiliates used several routes into victim networks, including compromised credentials...
The Amadey variant is the one exception ... configured to reach the command-and-control server ... and to persist through a scheduled task.
The Amadey variant is the one exception ... configured to reach the command-and-control server ... and to persist through a scheduled task.
Attackers continued gaining access through internet-facing devices, remote management tools, compromised accounts, and stolen credentials. Qilin affiliates used several routes into victim networks, including compromised credentials...
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The Amadey variant is the one exception ... configured to reach the command-and-control server ... and to persist through a scheduled task.
Malware authors rely on them to hide sensitive parts of their operations, whether it’s encrypting configuration, shellcode, concealing command-and-control (C2) traffic, or simply obfuscating strings to hinder analysis.
Attackers continued gaining access through internet-facing devices, remote management tools, compromised accounts, and stolen credentials. Qilin affiliates used several routes into victim networks, including compromised credentials...
The deletion engine is a legitimately signed IObit utility the operators abuse rather than code they wrote. The IObitUnlocker.exe staged on disk is the genuine, IObit-signed IObit Unlocker 1.6.0.16 ... and the kernel driver it loads ... is the matching genuine IObit component.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
819 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
157 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader variant delivered by one sample in the same archive family. Unlike the Saked variants, it is configured for command-and-control, downloads further executables, and persists via scheduled task.
Malware family that can provide stolen credentials and initial access to ransomware operators.
A malware family used to supply initial access and stolen credentials to ransomware operators.
Malware named as a target of Operation Endgame law enforcement action.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.