Amadey Bot
Amadey Bot is malware referenced as an information-stealing payload that played a central role in 2025 campaigns. The provided content states it is used for credential harvesting and persistence, and specifically notes persistence established via scheduled tasks disguised as legitimate services. It is also associated with infrastructure hunting artifacts, including reuse of the TLS certificate subject common name value "desas.digital," which can help identify related command-and-control infrastructure. The content places Amadey Bot among malware used in modern multi-stage operations and indicates that such activity commonly targets sectors including finance, healthcare, government, education, energy, utilities, retail, and e-commerce, though no actor-specific attribution is provided in the source material.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Discovery
1 technique
Discovery
Command and Control
1 technique
Command and Control
AsyncRAT Hardcoded Certificate Values cert.subject.cn="AsyncRAT Server" || cert.issuer.cn="AsyncRAT Server" ... Cobalt Strike Default Certificate Values cert.issuer.cn="Major Cobalt Strike" ... Quasar RAT Default certificate values. cert.subject.cn="Quasar Server CA" ... Sliver C2 Default Certificate values cert.subject.cn="multiplayer" && cert.issuer.cn="operators" ... Mythic C2 Default favicon hash and html title ... title=="Mythic"
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet and information stealer malware that establishes persistence and is used to harvest credentials and system information, often as a precursor to ransomware or extortion.
Bot malware family whose infrastructure can be identified here through re-used certificate values.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.