Description
FlawedAmmyy is a modified version of the Ammyy Admin remote access tool that gives cyberattackers undocumented remote control of infected systems. Criminal groups extracted the tool's source code after a leak and built their own malicious editions, which inherit the original software's legitimate network behavior and evade detection. Intrusion crews have used it for initial access and staging, and it frequently appears alongside information stealers and ransomware payloads.
Stats
- First seen
- March 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
22 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
Associated groups
Alert name variants
| Alert Name |
|---|
| Document-Excel.Trojan.FlawedAmmyy |
| Document-HTML.Backdoor.FlawedAmmyy |
| Document-HTML.Trojan.FlawedAmmyy |
| Document-Office.Trojan.FlawedAmmyy |
| Document-Word.Trojan.FlawedAmmyy |
| Script-Macro.Backdoor.FlawedAmmyy |
| Win32.Backdoor.FlawedAmmyy |
| Win32.Downloader.FlawedAmmyy |
| Win32.Trojan.FlawedAmmyy |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Doc.Downloader.FlawedAmmyy download attempt |