Netskope Threat Labs

Ammyy

ATP Sandbox Adv. Heuristics

Ammyy is a legitimate remote administration tool that lets support staff view and control remote desktops, but cyberattackers frequently abuse it to gain unauthorized access to victims. Because the tool operates through trusted software and legitimate infrastructure, intrusions that rely on it often bypass security tools that focus on executable malware. Criminal groups have distributed Ammyy through phishing lures and used it as a foothold for reconnaissance and credential theft.

First seen
January 2022
Last seen
October 2026
Alert Name
Win32.PUA.Ammyy
Win32.Rootkit.Ammyy
Win32.Trojan.Ammyy
Win64.Trojan.Ammyy