Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Amadey

37
Global rank
47 infographic chevron month
Month rank
47 infographic chevron week
Week rank
0
IOCs

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Infostealer
Type
Likely ex-USSR
Origin
13 October, 2018
First seen
27 August, 2026
Last seen
Also known as
Amadey Bot

How to analyze Amadey with ANY.RUN

Infostealer
Type
Likely ex-USSR
Origin
13 October, 2018
First seen
27 August, 2026
Last seen

IOCs

IP addresses
48.209.138.168
94.16.122.201
74.179.77.204
192.109.139.79
192.210.186.206
77.72.1.44
185.241.208.33
203.159.90.46
195.177.94.118
158.94.209.17
89.208.97.134
95.100.102.9
2.22.255.166
94.154.32.99
155.103.69.250
91.92.240.17
176.65.139.201
216.172.173.7
185.27.134.99
217.217.97.53
Hashes
a8a284f377cb9f21c53e5553234ecb693dc4c2c38f3306b6cde4aead5e05e913
92c6531a09180fae8b2aae7384b4cea9986762f0c271b35da09b4d0e733f9f45
c43668eec4a8d88a5b3a06a84f8846853fe33e54293c2db56899a5a5dfb4d944
41c91a9c93d76295746a149dce7ebb3b9ee2cb551d84365fff108e59a61cc304
30eedefcdd6870576babcba3fcd73f44ad563b4087bf8d1dd4e4663433f44858
3c3d7da255fb0241c53e030035b443c2fc1c3ae84109041fcc53347881b6c2bf
3ee8bf7fb2731b8350a5ecfdbda3f6a5935a9477f29e909b81ddcebe56887d12
180195558475b32abedb88b3103c06ee464148809986b78de32d8fdba897c516
8aae675bb39439e681976562dfa1f9d6f902bcffe540d31882f01b9e71d93584
44e8a165811c771298a104687d11bc11465181f939963c4c2224dc8ae151f2fa
933e2b77ee23a4bf6dab40964a47acecf928aa71f3ec6d21cc63fcb7c418f8ea
4412319ef944ebcca9581cbacb1d4e1dc614c348d1dfc5d2faaaad863d300209
036bacf3bd34365006eac2a78e4520a953a6250e9550dcf9c9d4b0678c225b4c
a8bd235303668981563dfb5aae338cb802817c4060e2c199b7c84901d57b7e1e
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
e09f42c398d688dce168570291f1f92d079987deda3099a34adb9e8c0522b30c
35bb2f189c643dcf52ecf037603d104035ecdc490bf059b7736e58ef7d821a09
d6a5fe39cd672781b256e0e3102f7022635f1d4bb7cfcc90a80fffe4d0f3877e
93332c49fab1deb87dac6cb5d313900cb20e6e1ba928af128a1d549a44256f68
Domains
students16.screenconnect.com
bmpincorporated.com
sixmexicos.com
gulf.moneroocean.stream
effectively32.infinityfree.me
mon-blanc-03.cfd
deliverymailreport.co.za
tarkioweb.com
release-assets.githubusercontent.com
sunix-technology.com
savannahadventureslimited.com
czd.ru.com
trf.kookapp.pro
inventorychanger.com
dns.google
wealthishealth.free.je
www.serdaregitim.com
t.me
eccmice.com
www.dropbox.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://maper.info/26tkr5
https://www.google.com/
https://urlhaus.abuse.ch/downloads/text/
http://91.92.242.236/files-129312398/files/file_e99b2c2df468a74c.exe
http://91.92.242.236/files-129312398/files/file_865d4f3e8fa37c05.exe
http://62.60.226.140/files/nels/cli.exe
http://91.92.242.236/files-129312398/files/file_542ee73385a72661.exe
http://193.104.58.65/rumpyu14th.png
http://193.104.58.65/img_gas.png
http://62.60.226.140/amka/random.exe
http://130.12.180.141/screenconnect.clientsetup.exe
http://62.60.226.140/files/1781548144/ql0ijz0.exe
http://62.60.226.140/files/7061144442/nxumfoe.exe
http://107.172.172.216/125/img_000358.png
http://193.104.58.65/obofile.png
http://62.60.226.140/files/gold/random.exe
http://91.92.242.236/files-129312398/files/file_28ae045da50f3847.exe
http://62.60.226.140/files/omega/file.exe
http://62.60.226.140/files/7782139129/tz2szvl.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2227
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6651
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10099
comments 0

What is Amadey malware

First seen about 5 years ago, Amadey is a modular bot that enables it to act as a loader or infostealer. It is designed to perform a range of malicious activities, including reconnaissance, data exfiltration, and loading additional payloads, which range from banking trojans to DDoS tools. It targets all versions of Microsoft Windows.

This malware’s capabilities include:

  • Privilege escalation
  • UAC bypassing
  • Keystroke logging
  • Screen capture
  • Downloading additional malware

While many adversaries primarily use this malware as a keylogger to steal credentials, it can also transform infected devices into spam email senders or add them to a botnet that adversaries use to launch DDoS attacks.

However, that’s not everything this threat is capable of. Owing to its modular design, Amadey can significantly expand its range of attack targets, enabling the extraction of a broader variety of information, such as files, login credentials, and cryptocurrency wallets.

Furthermore, current Amadey variants can recognize more than 14 antivirus solutions. This ability allows the malware to intelligently deploy a payload designed to evade the specific antivirus product installed on the compromised device.

In addition, this malware can move laterally, propagating to devices within the same network by pushing EternalBlue exploit onto victims. Although outdated, EternalBlue remains relevant, especially in public sectors like government and education, where end-of-life software usage is widespread.

As for the origin of this threat, little is known at this point. Older activity associated it with GandCrab campaigns, which might connect Amadey to the REvil gang or one of their affiliates. Additionally, Amadey is distributed on Slavic-speaking underground forums, which possibly places its origin in one of the ex-USSR territories.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

How to get more information from Amadey malware

In ANY.RUN, users can safely detonate Amadey samples and analyze it dynamically in a fully interactive cloud sandbox. Our service automatically collects and displays the execution data in user-friendly formats, such as this process graph.

Analyze malware for free in a fully interactive cloud sandbox – sign up now!

amadey Figure 1: A graph showing Amadey’s execution process

ANY.RUN detects Amadey using Suricata rules, allowing analysts to identify both new and old samples from this family. We also provide configuration details. This way, analysts can access important sample information like its version, options, and C2 addresses. The configuration is typically extracted within the first 10 seconds of launching a task. This ensures quick access to information.

amadey malware Figure 2: Amadey’s malware configuration

Amadey infostealer execution process

Once, when Amadey initiates its execution, the malware duplicates itself into a TEMP folder (sometimes naming itself bguuwe.exe). Following that, it modifies the Registry and creates a scheduled task to achieve persistence. Subsequently, Amadey sets up C2 communication and transmits a system profile to the adversary's server. While active, Amadey takes screenshots at regular intervals and stores them in the TEMP directory, ready to be transmitted to the C2 server with subsequent POST requests.

Amadey often serves as a loader for other malicious programs, such as in this task.

Also, Amadey has a very specific structure of POST requests, that can be used to identify it with a high degree of probability:

Figure 3: Information about infected machine, exfiltrated by Amadey and sent to C2 amadey malware

Distribution of Amadey

Amadey primarily relies on spear-phishing emails containing malicious attachments, such as Microsoft Office documents, to target specific organizations or individuals. The email content is carefully crafted to appear legitimate, enticing the victim to open the attachment.

Alternatively, Amadey can employ exploit kits (Fallout and Rig), drive-by downloads, or be dropped as a payload by other malware (in recent cases it was distributed by SmokeLoader).

Amadey malware conclusion

Amadey malware presents a notable challenge for cybersecurity researchers. Its persistence and evasion techniques, coupled with a highly customizable modular architecture, make it a high-level threat. Understanding its various infection vectors, exploitation methods, and malicious activities is essential to develop effective countermeasures and improve our overall cybersecurity posture.

You can efficiently detect and examine threats such as Amadey, with the help of ANY.RUN interactive sandbox, which provides analysis results in minutes.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

NetSupport RAT screenshot
NetSupport RAT
netsupport
NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.
Read More
Lynx screenshot
Lynx
lynx
Lynx is a double extortion ransomware: attackers encrypt important and sensitive data and demand a ransom for decryption simultaneously threatening to publish or sell the data. Active since mid-2024. Among techniques are terminating processes and services, privilege escalation, deleting shadow copies. Distribution by phishing, malvertising, exploiting vulnerabilities.
Read More
TrustConnect screenshot
TrustConnect
trustconnect
TrustConnect is a MaaS platform that disguises a Remote Access Trojan (RAT) as a legitimate Remote Monitoring and Management (RMM) tool. The operators built an AI-generated business website, obtained a fraudulently acquired Extended Validation (EV) code-signing certificate, and created fake customer statistics and documentation to make TrustConnect appear to the world — and to security tools — as a legitimate software company.
Read More
Loader screenshot
Loader
loader downloader
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More