Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityloader-delivery-mechanismremote-access-implantcybercrime-service-ecosystem

ResolverRAT, LummaStealer, and Amadey Linked in Multi-Tool Cybercrime Campaign

Updated 29d agoFirst seen Apr 25, 20264 sources

Researchers tied ResolverRAT, LummaStealer, and an Amadey botnet cluster to an active financially motivated campaign that has operated since at least late 2025 and uses fake browser update lures, staged loaders, and legitimate remote management tools for persistence. One analyzed chain used a Donut-decrypted, triple-protected .NET loader to deliver both ResolverRAT and LummaStealer at once, combining persistent remote access with credential and cryptocurrency wallet theft. The malware used layered obfuscation including .NET Reactor, custom transformations, AES-256-CBC, GZip, process hollowing, fragmented WinAPI reconstruction, forged compile timestamps, encrypted resource blobs, and certificate pinning, while operators rotated infrastructure across dozens of IPs, multiple domains, and hosting providers in Russia, the Netherlands, Germany, Poland, and elsewhere. Investigators also identified a fake Microsoft-themed domain, pat[.]microsoft-telemetry[.]at, and newly activated infrastructure such as kampf[.]huehnchenfarm[.]ru tied to the same ecosystem.

A parallel March 2026 investigation linked the fbf543 Amadey campaign to more than 50 payloads spanning at least 13 malware families, including Vidar, QuasarRAT, XWorm, AsyncRAT, Smoke Loader, and LummaStealer, with delivery through fake installers and hosting on infrastructure centered on Omegatech LTD (AS202412) and related abusive networks. Analysts found that the operators also abused nine legitimate, signed RMM tools from ConnectWise, DattoRMM, Atera, GoToResolve, and N-able, configuring them to beacon to attacker-controlled relays rather than compromising the vendors themselves. A separate Go-based loader unpacked LummaStealer with AES, RC4, and QuickLZ before hollowing AppLaunch.exe, reinforcing a playbook built around stealthy loaders, infostealer deployment, redundant access channels, and monetization consistent with an initial access broker or ransomware affiliate operation.

Share:
ResolverRAT, LummaStealer, and Amadey Linked in Multi-Tool Cybercrime Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Mar 12, 20263mo ago

Breakglass published analyses of ResolverRAT and Amadey fbf543 activity

On March 12, 2026, Breakglass Intelligence published multiple reports detailing the ResolverRAT/Lumma dual-payload loader, the broader ResolverRAT infrastructure, and the Amadey fbf543 malware distribution and RMM abuse campaign. The reports connected active infrastructure, malware samples, and hosting patterns across the operations.

Mar 10, 20263mo ago

Google WE1 certificate was issued for huehnchenfarm[.]ru

A new Google WE1 certificate for huehnchenfarm[.]ru was issued on March 10, 2026. This supported the assessment that the ResolverRAT-associated infrastructure was being actively maintained and refreshed.

Mar 9, 20264mo ago

Fresh ResolverRAT infrastructure appeared during investigation

Breakglass observed new infrastructure for the ResolverRAT-linked operation on March 9, 2026, including kampf[.]huehnchenfarm[.]ru and IP address 45[.]141[.]119[.]34. The finding showed the campaign was still actively evolving during the investigation.

Nine RMM samples from Amadey fbf543 were uploaded to MalwareBazaar

Researchers linked nine legitimate but attacker-configured RMM installers uploaded to MalwareBazaar on March 9, 2026 to the fbf543 campaign. The tools came from ConnectWise, DattoRMM, Atera, GoToResolve, and N-able and were used for stealthy persistence.

Mar 6, 20264mo ago

Amadey fbf543 campaign began distributing malware payloads

The Amadey botnet campaign tagged fbf543 distributed more than 50 payloads across at least 13 malware families between March 6 and March 10, 2026. Payloads included LummaStealer, Vidar, QuasarRAT, XWorm, AsyncRAT, Smoke Loader, and multiple abused remote management tools.

Mar 5, 20264mo ago

MalwareBazaar received a ResolverRAT-linked .NET sample

A Donut-decrypted .NET executable later tied to the broader ResolverRAT cybercrime campaign was submitted to MalwareBazaar on March 5, 2026. Breakglass used this sample to analyze the malware's obfuscation, certificate pinning, and shared infrastructure.

Jan 1, 20266mo ago

Linked ResolverRAT/Lumma samples were observed from January 2026

Researchers identified five linked malware samples observed from January through March 2026 that shared the same imphash, indicating a common build pipeline and active maintenance. These samples delivered ResolverRAT and LummaStealer together through a heavily protected .NET loader.

Dec 1, 20257mo ago

Dormant ResolverRAT infrastructure was activated together

The five Registrar.eu domains associated with the ResolverRAT ecosystem were activated in December 2025 after months of dormancy. This marked a coordinated expansion or operationalization of the campaign's infrastructure.

Nov 1, 20258mo ago

ResolverRAT-linked campaign became active by at least November 2025

Breakglass assessed the broader cybercrime operation supporting ResolverRAT, PureRAT, PureHVNC, PureLogs Stealer, and likely Lumma/ZgRAT had been active since at least November 2025. The campaign used ClearFake/ClickFix fake browser update lures and a Donut-based in-memory loader to deliver obfuscated .NET malware.

Mar 1, 20251y ago

Registrar.eu domains tied to ResolverRAT ecosystem were batch-registered

Investigators found five domains later used in the ResolverRAT-linked command-and-control ecosystem were registered together through Registrar.eu in March 2025. These domains then remained dormant for roughly nine months before activation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

67 LINKEDOpen in app
Affected products
7 linked
.Net FrameworkCloudflareRemote Desktop ProtocolAnydeskScreenconnectZoomUbuntu
Organizations
37 linked
CloudflareBreakglass IntelligenceNameCheapConnectwiseOmegatech LTDDedik Services LimitedGlobalSignSectigoOVHcloudHosting ConceptsN-AbleMicrosoft CorporationAnyDesk Software GmbHBitsightAEZA GroupNICENICNameSiloLet's EncryptAteraGoTo Technologies USA, LLCProton66 OOOHyonixGoogle Trust ServicesCloudzyDEMENIN B.V.Online Connect LtdIntegen IncRica Web ServicesGlobal-Data SystemPFCLOUDLanedonetLainSMARTNET LIMITEDVMHeaven.ioH2NEXUS LTDDatto, LLCAUROLOGIC
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.