Netskope Threat Labs

FlawedAmmyy

ATP Sandbox Adv. HeuristicsNetskope IPS

FlawedAmmyy is a modified version of the Ammyy Admin remote access tool that gives cyberattackers undocumented remote control of infected systems. Criminal groups extracted the tool's source code after a leak and built their own malicious editions, which inherit the original software's legitimate network behavior and evade detection. Intrusion crews have used it for initial access and staging, and it frequently appears alongside information stealers and ransomware payloads.

First seen
March 2022
Last seen
October 2026

22 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
Document-Excel.Trojan.FlawedAmmyy
Document-HTML.Backdoor.FlawedAmmyy
Document-HTML.Trojan.FlawedAmmyy
Document-Office.Trojan.FlawedAmmyy
Document-Word.Trojan.FlawedAmmyy
Script-Macro.Backdoor.FlawedAmmyy
Win32.Backdoor.FlawedAmmyy
Win32.Downloader.FlawedAmmyy
Win32.Trojan.FlawedAmmyy