Executive Summary
FlawedAmmyy is a Windows RAT that uses leaked Ammyy Admin code to provide remote control, logging, and file transfer to attackers. Its use of legitimate remote‑desktop protocols hides its activity from many security solutions. The malware can maintain persistence, allowing prolonged data exfiltration and lateral movement.
Enhanced Description
FlawedAmmyy is a Windows‑based remote access trojan (RAT) that emerged in early 2016. The development team leveraged leaked source code from an older version of the commercial Ammyy Admin tool, incorporating its core remote‑control framework while adding malicious extensions such as backdoors for persistence and covert data exfiltration. The malware enables a threat actor to gain complete control over an infected system: it captures screenshots, logs keystrokes, and can execute arbitrary shell commands through a reversible tunnel that masquerades as legitimate remote‑desktop traffic. It also supports file transfer, process management, and the injection of DLLs into other processes to evade detection. Impact is significant because FlawedAmmyy’s code base mirrors legitimate Ammyy Admin, which leads security solutions to misclassify it or overlook it as benign. Its persistence mechanisms allow long‑term compromise, enabling attackers to maintain a foothold, exfiltrate sensitive data, and pivot within the victim network for further exploitation. Overall, FlawedAmmyy showcases how open‑source or leaked code can be repurposed into sophisticated malware capable of bypassing standard detection engines while providing an attacker with comprehensive remote capabilities.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the described capabilities is moderate. The primary source references only the existence of a RAT using leaked Ammyy Admin code, with no publicly available samples or detailed technical reports. Key features are inferred from comparable RAT families and general behavior patterns typical of remote‑desktop based malware.
FlawedAmmyy is a remote access tool (RAT) that was first seen in early 2016. The code for FlawedAmmyy was based on leaked source code for a version of Ammyy Admin, a remote access software.(Citation: Proofpoint TA505 Mar 2018)