Executive Summary
Amadey is an enduring Windows Trojan bot that establishes persistent, web‑based command and control connections to collect system data, execute remote commands, and exfiltrate information. It has surfaced alongside high-profile cybercrime operations, indicating a capability designed for large‑scale compromise and revenue extraction.
Enhanced Description
Amadey is a Windows‐based Trojan bot first identified in reports from October 2018 that has subsequently been linked to wider cybercrime operations such as the Korean FSI TA505 case and a BlackBerry investigation in 2020. The malware functions as a client component in a larger botnet, establishing command and control (C&Co) connections over standard web protocols to receive instructions and upload stolen data. Once executed on an infected host, Amadey achieves persistence by creating a startup registry key and may also employ scheduled tasks to maintain its presence. It leverages remote execution capabilities to run arbitrary commands supplied via the C&C channel, enabling attackers to deploy additional payloads such as ransomware or credential harvesters. The bot routinely gathers system information—including usernames, machine identifiers, installed software lists—and exfiltrates this data over HTTPS to evade detection. The threat group behind Amadey appears to focus on mass compromise and revenue generation through stealthy distribution channels. By maintaining a covert online presence and using legitimate web protocols for C&C traffic, the malware remains difficult to isolate in heterogeneous network environments, underscoring the need for advanced behavioral monitoring tools.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on limited public references; detailed technical footprints such as specific file names, registry keys, or network indicators are not provided. Confidence in high‑level capabilities is moderate, but precise fingerprinting requires further analysis.
Amadey is a Trojan bot that has been used since at least October 2018.(Citation: Korean FSI TA505 2020)(Citation: BlackBerry Amadey 2020)