Amadey
Amadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware. Source: MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 24 Jun 2026 · last seen on 24 Jun 2026
News
- ESET participa en la Operación Endgame para interrumpir la botnet Amadey y el infostealer StealcWeLiveSecurity · 24 Jun 2026
Appears alongside
MITRE ATT&CK techniques
Execution
Persistence
Discovery
T1016System Network Configuration Discovery 4 Sigma rulesT1033System Owner/User Discovery 26 Sigma rulesT1082System Information Discovery 18 Sigma rulesT1083File and Directory Discovery 17 Sigma rulesT1518.001Security Software Discovery 5 Sigma rulesT1614System Location Discovery 2 Sigma rules
Collection
Command and Control
T1071.001Web Protocols 39 Sigma rulesT1105Ingress Tool Transfer 40 Sigma rulesT1568.001Fast Flux DNS
Exfiltration
Stealth
T1027Obfuscated Files or Information 61 Sigma rulesT1140Deobfuscate/Decode Files or Information 17 Sigma rules
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗ malpedia.caad.fkie.fraunhofer.de ↗