Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware FlawedAmmyy

FlawedAmmyy

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

FlawedAmmyy is a Windows RAT that uses leaked Ammyy Admin code to provide remote control, logging, and file transfer to attackers. Its use of legitimate remote‑desktop protocols hides its activity from many security solutions. The malware can maintain persistence, allowing prolonged data exfiltration and lateral movement.

Enhanced Description

FlawedAmmyy is a Windows‑based remote access trojan (RAT) that emerged in early 2016. The development team leveraged leaked source code from an older version of the commercial Ammyy Admin tool, incorporating its core remote‑control framework while adding malicious extensions such as backdoors for persistence and covert data exfiltration. The malware enables a threat actor to gain complete control over an infected system: it captures screenshots, logs keystrokes, and can execute arbitrary shell commands through a reversible tunnel that masquerades as legitimate remote‑desktop traffic. It also supports file transfer, process management, and the injection of DLLs into other processes to evade detection. Impact is significant because FlawedAmmyy’s code base mirrors legitimate Ammyy Admin, which leads security solutions to misclassify it or overlook it as benign. Its persistence mechanisms allow long‑term compromise, enabling attackers to maintain a foothold, exfiltrate sensitive data, and pivot within the victim network for further exploitation. Overall, FlawedAmmyy showcases how open‑source or leaked code can be repurposed into sophisticated malware capable of bypassing standard detection engines while providing an attacker with comprehensive remote capabilities.

Key Capabilities

  • Remote system administration via tunneled desktop protocol
  • Keystroke logging and screenshot capture
  • Command execution and shell access
  • File upload and download
  • Process enumeration and injection
  • Persistence through scheduled tasks or registry modification

ATT&CK Techniques

T1071
T1059.001
T1021.004
T1105
T1033

Recommended Actions

  • Deploy up‑to‑date anti‑malware signatures that detect FlawedAmmyy variants

Suggested Tags

RAT
Remote Access Tool
Ammyy Admin
Windows
2016
Persistence
Keystroke Logging
File Exfiltration

Confidence Assessment

The confidence level in the described capabilities is moderate. The primary source references only the existence of a RAT using leaked Ammyy Admin code, with no publicly available samples or detailed technical reports. Key features are inferred from comparable RAT families and general behavior patterns typical of remote‑desktop based malware.

Description

FlawedAmmyy is a remote access tool (RAT) that was first seen in early 2016. The code for FlawedAmmyy was based on leaked source code for a version of Ammyy Admin, a remote access software.(Citation: Proofpoint TA505 Mar 2018)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.