Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Amadey

38
Global rank
48
Month rank
50 infographic chevron week
Week rank
0
IOCs

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Infostealer
Type
Likely ex-USSR
Origin
13 October, 2018
First seen
17 September, 2026
Last seen
Also known as
Amadey Bot

How to analyze Amadey with ANY.RUN

Infostealer
Type
Likely ex-USSR
Origin
13 October, 2018
First seen
17 September, 2026
Last seen

IOCs

IP addresses
172.65.251.78
150.171.109.104
2.23.246.9
152.53.49.102
52.123.243.208
48.192.1.65
108.138.7.107
52.110.17.63
150.171.109.193
65.8.131.76
150.171.27.11
34.49.229.81
74.179.77.204
162.125.72.15
34.149.206.255
204.79.197.203
150.171.28.11
150.171.109.101
162.159.143.12
172.211.123.249
Hashes
11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5
c64775436f34a6d26e276bbbc97becda2d4c73f15d70d5b13587d72123dfc5fd
138c240382304f350383b02ed56c69103a9431c0544eb1ec5dcd7dec7a555dd9
0f404764d07a6ae2ef9e1e0e8eaac278b7d488d61cf1c084146f2f33b485f2ed
bcc0e6458249433e8cba6c58122b7c0efa9557cbc8fb5f9392eed5d2579fc70b
4d0bd3228ab4cc3e5159f4337be969ec7b7334e265c99b7633e3daf3c3fcfb62
47576cae321c80e69c7f35205639680bf28010111e86e228ed191b084fac6b91
5b8d47451f847c1bde12caca3739ca29860553c0b6399ee990d51b26f9a69722
e2991a6f7a7a4d8d3c4c97947298fd5bacb3eaa2f898cee17f5e21a9861b9626
0aa66dff8a7ae570fee83a803f8f5391d9f0c9bd6311796592d9b6e8e36be6fc
a0415f14f5d72ad24e9c3a5c91517a0e3d22e1adbc3505c0c6e918b961f7a07d
c15ab85438728bf2c60d72b1a66af80e8b1ce3cf5eb08ba6421ff1b2f73acdf4
29d93dee7c01b2264778bc6b75f6ef76ea6ac53e9f4a334d83707229e7f482d2
b6cd5c6f2b54d89142679d599ed0a5dee6955a3b3f6b6673e46afe7a5a303cdc
6c15cb256b1c22170292589c6f589e64e164eb36ec7e84f0bd48149babb7c5fc
804efa345c5bbbad2449c318a7a3f5b31f4234712aad23dc49b3fb5aa33b7a57
4b7e76aeb75289faca76434ea6e9874e9504ad2bc3d8d47550eadbcc8294857e
232d6fe34d7151920232eaae9c515f36400ab64136dcc5b802d6245ac6f5d56b
afe6ed6eb5d07c45b6b928a48bc5ef57efcf61602d36ff9fbde4a8ea3fa6df75
f80e05533d1a1494c32f9412e9ad2d9c11faf9ae0668a6f9d1fa5ceedc6870e2
Domains
settings-win.data.microsoft.com
go.microsoft.com
edge-consumer-static.azureedge.net
www.ezic.net
ecs.office.com
update.googleapis.com
static.wixstatic.com
www.microsoft.com
edge.microsoft.com
login.live.com
ezic.net
client.wns.windows.com
crl.microsoft.com
slscr.update.microsoft.com
th.bing.com
dns.google
ocsp.digicert.com
frog.wix.com
www.dropbox.com
fe3cr.delivery.mp.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:ss_wg47rtyrtgj9uzansj9ppitly1te9ouslost5lmm&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://ezic.net/
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://ezic.net/
https://www.ezic.net/
https://www.ezic.net/_partials/wix-thunderbolt/dist/clientworker.662e0928.bundle.min.js
https://www.ezic.net/_api/v1/access-tokens
https://www.ezic.net/_api/tag-manager/api/v1/tags/sites/a18995d4-ba1a-49e2-a3cd-426e0942a644?wixsite=false&htmlsiteid=e4656611-ac7f-40bd-94b0-2f935fad3fd1&language=ru
https://static.wixstatic.com/media/643967_722add5cf6be49ecb97c862fca88bf94~mv2.png/v1/fill/w_49,h_33,al_c,q_85,usm_0.66_1.00_0.01,blur_2,enc_avif,quality_auto/%d0%bb%d0%be%d0%b3%d0%be%d1%81%d0%bb%d0%be%d0%b2%d0%be.png
https://static.wixstatic.com/media/643967_bb3a966859624b88a1609ab0b43d1264~mv2.webp/v1/fill/w_147,h_57,al_c,q_80,usm_0.66_1.00_0.01,blur_2,enc_avif,quality_auto/d0e70b4cbb9ab8afb1bc1065a3f8487a_hero.webp
https://static.wixstatic.com/media/643967_970f58d1cf9f43a9bfbfbc549fd9c71b~mv2.webp/v1/fill/w_147,h_59,al_c,q_80,usm_0.66_1.00_0.01,blur_2,enc_avif,quality_auto/apex_webp_4c378b906ee06aefaaa7454541b777d6.webp
https://static.wixstatic.com/media/643967_1d0826b7c6c641858253b94bbcb16b22~mv2.webp/v1/fill/w_147,h_59,al_c,q_80,usm_0.66_1.00_0.01,blur_2,enc_avif,quality_auto/cod_webp_81bc0ebd4269802507fe98ab3347762a.webp
https://static.wixstatic.com/media/643967_3c2ce226c02d4e7db75305fa8d7edcaa~mv2.webp/v1/fill/w_147,h_59,al_c,q_80,usm_0.66_1.00_0.01,blur_2,enc_avif,quality_auto/cs2_webp_b0ddb82ec436f4dbf32709ade9334209.webp
https://static.wixstatic.com/media/643967_cfc46a01a6a249de921f035977171325~mv2.webp/v1/fill/w_147,h_59,al_c,q_80,usm_0.66_1.00_0.01,blur_2,enc_avif,quality_auto/dayz_webp_c345ba8efa310e0ffca3e30ec7703ebf.webp
https://static.wixstatic.com/media/643967_796e73da9f8346d4bccbbc8d9b630404~mv2.webp/v1/fill/w_147,h_59,al_c,q_80,usm_0.66_1.00_0.01,blur_2,enc_avif,quality_auto/delta_webp_093240134a32b08f9d65c0b8c781c5f3.webp
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 1613
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 3443
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 6576
comments 0

What is Amadey malware

First seen about 5 years ago, Amadey is a modular bot that enables it to act as a loader or infostealer. It is designed to perform a range of malicious activities, including reconnaissance, data exfiltration, and loading additional payloads, which range from banking trojans to DDoS tools. It targets all versions of Microsoft Windows.

This malware’s capabilities include:

  • Privilege escalation
  • UAC bypassing
  • Keystroke logging
  • Screen capture
  • Downloading additional malware

While many adversaries primarily use this malware as a keylogger to steal credentials, it can also transform infected devices into spam email senders or add them to a botnet that adversaries use to launch DDoS attacks.

However, that’s not everything this threat is capable of. Owing to its modular design, Amadey can significantly expand its range of attack targets, enabling the extraction of a broader variety of information, such as files, login credentials, and cryptocurrency wallets.

Furthermore, current Amadey variants can recognize more than 14 antivirus solutions. This ability allows the malware to intelligently deploy a payload designed to evade the specific antivirus product installed on the compromised device.

In addition, this malware can move laterally, propagating to devices within the same network by pushing EternalBlue exploit onto victims. Although outdated, EternalBlue remains relevant, especially in public sectors like government and education, where end-of-life software usage is widespread.

As for the origin of this threat, little is known at this point. Older activity associated it with GandCrab campaigns, which might connect Amadey to the REvil gang or one of their affiliates. Additionally, Amadey is distributed on Slavic-speaking underground forums, which possibly places its origin in one of the ex-USSR territories.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

How to get more information from Amadey malware

In ANY.RUN, users can safely detonate Amadey samples and analyze it dynamically in a fully interactive cloud sandbox. Our service automatically collects and displays the execution data in user-friendly formats, such as this process graph.

Analyze malware for free in a fully interactive cloud sandbox – sign up now!

amadey Figure 1: A graph showing Amadey’s execution process

ANY.RUN detects Amadey using Suricata rules, allowing analysts to identify both new and old samples from this family. We also provide configuration details. This way, analysts can access important sample information like its version, options, and C2 addresses. The configuration is typically extracted within the first 10 seconds of launching a task. This ensures quick access to information.

amadey malware Figure 2: Amadey’s malware configuration

Amadey infostealer execution process

Once, when Amadey initiates its execution, the malware duplicates itself into a TEMP folder (sometimes naming itself bguuwe.exe). Following that, it modifies the Registry and creates a scheduled task to achieve persistence. Subsequently, Amadey sets up C2 communication and transmits a system profile to the adversary's server. While active, Amadey takes screenshots at regular intervals and stores them in the TEMP directory, ready to be transmitted to the C2 server with subsequent POST requests.

Amadey often serves as a loader for other malicious programs, such as in this task.

Also, Amadey has a very specific structure of POST requests, that can be used to identify it with a high degree of probability:

Figure 3: Information about infected machine, exfiltrated by Amadey and sent to C2 amadey malware

Distribution of Amadey

Amadey primarily relies on spear-phishing emails containing malicious attachments, such as Microsoft Office documents, to target specific organizations or individuals. The email content is carefully crafted to appear legitimate, enticing the victim to open the attachment.

Alternatively, Amadey can employ exploit kits (Fallout and Rig), drive-by downloads, or be dropped as a payload by other malware (in recent cases it was distributed by SmokeLoader).

Amadey malware conclusion

Amadey malware presents a notable challenge for cybersecurity researchers. Its persistence and evasion techniques, coupled with a highly customizable modular architecture, make it a high-level threat. Understanding its various infection vectors, exploitation methods, and malicious activities is essential to develop effective countermeasures and improve our overall cybersecurity posture.

You can efficiently detect and examine threats such as Amadey, with the help of ANY.RUN interactive sandbox, which provides analysis results in minutes.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More