Description
Amadey is a botnet and malware loader that criminal developers have sold on underground forums since around 2018. It gives buyers a simple panel for managing infected systems and offers paid modules, including an information stealer, that collect credentials and system data from victims. Cyberattackers commonly distribute Amadey through phishing emails, malvertising, and fake software downloads, and they use it to install heavier payloads such as information stealers and remote access trojans.
Stats
- First seen
- May 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
17 techniques across 8 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Amadey |
| Gen:Variant.Amadey.1 |
| Gen:Variant.Amadey.4 |
| Script-PowerShell.Downloader.Amadey |
| Script-PowerShell.Trojan.Amadey |
| Script.Downloader.Amadey |
| Win32.Downloader.Amadey |
| Win32.Exploit.Amadey |
| Win32.Infostealer.Amadey |
| Win32.Ransomware.Amadey |