#Amadey
Malware/Tool
2019-05-16 • 한국어 구사 Konni 조직, 블루 스카이 작전 'Amadey' 러시아 봇넷 활용
Amadey is a commodity Trojan and bot used for credential harvesting, remote control, system profiling, and delivery of additional malware. Observed delivery included a malicious Word document with a VBA macro, spear-phishing attachments, and an executable disguised with the filename and icon of a KakaoTalk update. One Windows chain injected into its own process, contacted command-and-control infrastructure, downloaded an archive to a public directory, launched a DLL through rundll32, and deleted staging files. The bot reported system ID, version, privilege level, architecture, Windows version, computer name, and username to its server. MITRE ATT&CK S1025.
-
5
Tagged Reports
-
3
Unique Authors
-
1,668
Active Days