Affected platforms
The following platforms are known to be affected:
Threat details
Despite being comparatively expensive, it has proven popular with a number of attackers, including the TA505 advanced persistent threat group, as a dropper for their own malware.
Amadey is delivered as ZIP file attachments distributed via spam email campaigns. When opened, these attachments will redirect the user to a compromised website, where they will be asked to provide their details (it is unclear if this is a phishing attempt or is intended to trick the user into thinking the site is legitimate) before downloading Amadey.
Once this is done, Amadey will create registry entries to disable security services and maintain persistence. It then connects to several different command and control servers to download any intended payloads, which are then subsequently installed.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:55 pm