Netskope Threat Labs

Amadey

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Amadey is a botnet and malware loader that criminal developers have sold on underground forums since around 2018. It gives buyers a simple panel for managing infected systems and offers paid modules, including an information stealer, that collect credentials and system data from victims. Cyberattackers commonly distribute Amadey through phishing emails, malvertising, and fake software downloads, and they use it to install heavier payloads such as information stealers and remote access trojans.

First seen
May 2022
Last seen
October 2026

17 techniques across 8 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

  • T1027Obfuscated Files or Information
  • T1140Deobfuscate/Decode Files or Information

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1518Software Discovery
  • T1614System Location Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Trojan.Amadey
Gen:Variant.Amadey.1
Gen:Variant.Amadey.4
Script-PowerShell.Downloader.Amadey
Script-PowerShell.Trojan.Amadey
Script.Downloader.Amadey
Win32.Downloader.Amadey
Win32.Exploit.Amadey
Win32.Infostealer.Amadey
Win32.Ransomware.Amadey