{"id":16087,"date":"2026-06-25T18:47:26","date_gmt":"2026-06-25T18:47:26","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=16087"},"modified":"2026-06-25T18:47:27","modified_gmt":"2026-06-25T18:47:27","slug":"eset-takes-half-in-operation-endgame-to-disrupt-amadey-and-stealc","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=16087","title":{"rendered":"ESET takes half in Operation Endgame to disrupt Amadey and Stealc"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A yr in the past, ESET Analysis was a part of two main operations that disrupted a number of the main cybercriminal operations on the time, Lumma Stealer and Danabot. Extra not too long ago, our researchers are as soon as once more collaborating with personal companions and legislation enforcement, however this time taking purpose on the Amadey botnet and Stealc infostealer, each offered through malware-as-a-service (MaaS) choices. Operation Endgame \u2013 coordinated by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/24\/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them\/\" target=\"_blank\" rel=\"noopener\">Microsoft Digital Crimes Unit<\/a> (DCU), <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bitsight.com\/blog\/bitsight-aids-disruption-efforts-on-amadey-malware-and-stealc-malware\" target=\"_blank\" rel=\"noopener\">BitSight<\/a>, Lumen, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.mbsd.jp\/research\/20260624\/amadey-c2-en\/\" target=\"_blank\" rel=\"noopener\">Mitsui Bussan Safe Instructions<\/a> (MBSD), and different companions \u2013 focused all recognized community infrastructure utilized by Amadey and Stealc associates in an effort to cripple their cybercriminal operations.<\/p>\n<p>ESET contributed to this effort by offering technical analyses, statistical info, recognized command and management (C&amp;C) servers, encryption keys, marketing campaign and construct identifiers, and different risk intelligence collected throughout our long-term monitoring of each malware households.<\/p>\n<blockquote>\n<p><strong>Key factors of this blogpost:<\/strong><\/p>\n<ul>\n<li>ESET took half within the coordinated, world Operation Endgame to disrupt Amadey and Stealc.<\/li>\n<li>Operation Endgame impacted round 50 domains and practically 200 energetic IP-based C&amp;C servers related to Amadey and Stealc.<\/li>\n<li>ESET offered technical analyses, statistical info, recognized C&amp;C servers, encryption keys, marketing campaign identifiers, and different insights.<\/li>\n<li>We offer an outline of the MaaS ecosystem on the affiliate degree for each malware households.<\/li>\n<li>We describe how we clustered Amadey and Stealc exercise.<\/li>\n<li>We summarize the technical properties most related to monitoring and disruption, together with C&amp;C communications, embedded identifiers, and encryption keys.<\/li>\n<li>We element overlaps between actions of Amadey and associates of Lumma Stealer.<\/li>\n<\/ul>\n<\/blockquote>\n<h2>Disruption contribution<\/h2>\n<p>ESET Analysis has been monitoring each the Amadey botnet and Stealc infostealer for the previous three years. For this disruption operation, we shared statistics masking This fall 2025 by means of H1 2026, together with technical indicators and configuration information extracted from processed malware samples.<\/p>\n<p>Our automated techniques have been dissecting Amadey and Stealc samples and figuring out the fields most related for large-scale monitoring. These embrace C&amp;C servers, construct identifiers, encryption keys, URL paths, marketing campaign identifiers, and different embedded values utilized by the malware households throughout communication with attacker-controlled infrastructure.<\/p>\n<p>A serious focus of our work was discovering dependable strategies to deal with the big quantity of processed samples and to cluster them. This was notably helpful as a result of each Amadey and Stealc are bought as companies. As such, the malware samples are distributed and operated by associates, typically operating their very own infrastructure, producing or requesting their very own builds, and orchestrating their very own campaigns. Figuring out exercise clusters in such ecosystems permits us to identify high-priority targets for disruptions like this one.<\/p>\n<p>Sharing technical analyses, statistical info, and risk intelligence, similar to C&amp;C server lists, affiliate identifiers, and encryption keys, allows legislation enforcement companies to determine, prioritize, and act in opposition to infrastructure with a excessive diploma of confidence. IoCs additionally assist distinguish between particular person clusters, shared infrastructure, and high-impact botnets whose disruption is more likely to have the best affect on the general risk panorama. In the end, the disruption affected round 50 domains and practically 200 energetic IPs used as C&amp;C servers for both Amadey or Stealc.<\/p>\n<h3>Disrupted malware households<\/h3>\n<p>Amadey is a modular malware loader. Its most important goal is to distribute extra malware to compromised techniques, though it additionally gives modules for information exfiltration and distant entry.<\/p>\n<p>Stealc, in distinction, is a typical infostealer as a service. It targets credentials, cookies, cryptocurrency wallets, browser extensions, and information whose names match affiliate-defined patterns.<\/p>\n<p>Each malware households are bought as companies and marketed on darknet boards. For visibility into darknet boards, we used <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/flare.io\/\" target=\"_blank\" rel=\"noopener\">Flare.io<\/a>, a risk intelligence platform that displays underground communities. In each ecosystems, associates obtain a self-hosted administration panel that have to be deployed on their very own server infrastructure. This requires a sure degree of technical talent from associates and in addition provides them direct management over sufferer information and payload distribution.<\/p>\n<p>This mannequin differs from different MaaS ecosystems. For instance, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/danabot-analyzing-fallen-empire\/\" target=\"_blank\" rel=\"noopener\">Danabot<\/a> associates can select to lease C&amp;C infrastructure as a service, whereas <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-takes-part-global-operation-disrupt-lumma-stealer\/\" target=\"_blank\" rel=\"noopener\">Lumma Stealer<\/a> used an exfiltration community absolutely managed by its operators. Within the case of Amadey and Stealc, associates are chargeable for deploying and working their very own infrastructure, making disruption efforts harder, which is why the clustering strategy was important.<\/p>\n<p>Whereas distribution strategies in the end depend upon every particular person affiliate, ESET telemetry persistently confirmed that each malware households had been delivered by means of a variety of channels. The most typical strategies included faux software program updates, cracked software program installers, and third-party malware loaders.<\/p>\n<p>Amadey used a pay-per-rebuild mannequin. Associates bought a license after which paid a further price every time they wanted to generate a brand new construct, for instance when rotating to a brand new C&amp;C server. In different phrases, Amadey operators didn&#8217;t present associates with a builder instrument; as an alternative, samples had been compiled on request for every affiliate.<\/p>\n<p>Stealc took a extra affiliate-friendly strategy, providing limitless construct era (Determine 1) as a part of its subscription. This lowered the operational value of rotating C&amp;C infrastructure and made it simpler for associates to generate new samples as wanted.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 1. Stealc panel build generation feature\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-1.png\" alt=\"Figure 1. Stealc panel build generation feature\" width=\"\" height=\"\"\/><figcaption><em>Determine 1. Stealc panel construct era function<\/em><\/figcaption><\/figure>\n<p>Making an attempt to keep away from impersonation scams, operators of each companies explicitly instructed potential associates on darknet boards to contact them solely by means of official channels. Amadey directed consumers to personal messages on the darknet discussion board the place it&#8217;s marketed, whereas Stealc used personal messages on darknet boards or Telegram.<\/p>\n<h2>Amadey<\/h2>\n<p>Amadey is a modular malware loader that has been marketed on darknet boards by account identify InCrease since October 2018. Over time, it has turn out to be one of many extra steady and actively maintained malware households, with ongoing help offered by means of darknet discussion board channels.<\/p>\n<p>Our telemetry detection charge, proven in Determine 2, signifies that Amadey was noticed globally with no particular regional focus, though the very best detection charges had been noticed in India, Turkey, Egypt, Mexico, and Spain.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 2. Distribution of Amadey \u2013 detection heatmap (2025\u2013present)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-2.png\" alt=\"Figure 2. Distribution of Amadey \u2013 detection heatmap (2025\u2013present)\" width=\"\" height=\"\"\/><figcaption><em>Determine 2. Distribution of Amadey \u2013 detection heatmap (2025\u2013current)<\/em><\/figcaption><\/figure>\n<p>The first operate of Amadey is to distribute extra malware to victims. Apart from that, it gives three modules for additional information exfiltration and entry: clipboard monitoring, credential theft, and VNC-based distant entry.<\/p>\n<p>The service is priced at US$600, paid in Bitcoin, for a single license, with a further US$50 charged per rebuild. This implies associates incur a price every time they generate a brand new construct, similar to when rotating to a contemporary C&amp;C server. This pricing has remained largely unchanged because the earliest marketed variations, suggesting a steady and established buyer base.<\/p>\n<p>Over time we&#8217;ve got noticed ongoing model updates (Determine 3) and energetic improvement of Amadey. Essentially the most important milestone in Amadey\u2019s improvement got here in August 2020 (v1.99.5), when the whole codebase was fully rewritten. The second main evolution arrived within the launch of v5.03 in October 2024, which delivered a dense wave of recent capabilities: hVNC with reverse join, MSI silent installer help, RDP enabling, cmd.exe execution with SYSTEM privileges, and built-in help for encrypted payloads. Total, the vast majority of the opposite, extra minor updates served one implicit however fixed goal: evading AV detections as they appeared.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 3. Amadey versions timeline\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-3.png\" alt=\"Figure 3. Amadey versions timeline\" width=\"\" height=\"\"\/><figcaption><em>Determine 3. Amadey variations timeline<\/em><\/figcaption><\/figure>\n<h3>Technical overview<\/h3>\n<p>Every Amadey pattern comprises at the least one hardcoded C&amp;C server URL, with the configuration supporting as much as three entries. Samples additionally embed an RC4 key used for encrypting communications with the C&amp;C server.<\/p>\n<p>Our evaluation confirmed that the RC4 key extracted from every pattern serves as a dependable cluster identifier, permitting us to cluster samples into particular person botnets, which we focus on in additional element within the <em><a rel=\"nofollow\" target=\"_blank\" href=\"#Clustering\">Clustering<\/a> <\/em>part.<\/p>\n<p>A second hardcoded worth, internally known as <span style=\"font-family: courier new, courier, monospace;\">sd<\/span>, is a random-looking six-character hexadecimal string matching the sample <span style=\"font-family: courier new, courier, monospace;\">[0-9a-f]{6}<\/span>. It&#8217;s transmitted in the course of the preliminary C&amp;C handshake and almost definitely identifies a selected construct inside an affiliate\u2019s deployment. Though it&#8217;s generally known as a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/posts\/teethador_swisscom-tdr-threat-brief-unmasking-amadey-ugcPost-7403675666841456640-mwlg\/\">marketing campaign ID<\/a> or <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/amadey-threat-analysis-and-detections.html\">Amadey ID<\/a> by researchers, Amadey\u2019s pay-per-build enterprise mannequin means that it extra precisely represents a construct identifier.<\/p>\n<p>Every pattern additionally carries a model quantity. Our evaluation focuses on model v5.x, which has been the dominant variant noticed in ESET telemetry because the starting of 2025.<\/p>\n<p>This bot additionally checks the sufferer\u2019s keyboard structure. If it matches a structure related to a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/posts\/teethador_swisscom-tdr-threat-brief-unmasking-amadey-activity-7403675667952844800-tFQL\/\" target=\"_blank\" rel=\"noopener\">CIS nation<\/a>, all community communication is silently rejected. Risk actors working from Japanese Europe generally use the sort of built-in safeguard to keep away from affecting companies and governmental entities within the area, lowering the chance of consideration or prosecution by native authorities. As well as, these operators typically comply with such practices to keep away from potential backlash from their friends for concentrating on \u201ctheir very own folks\u201d or <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/g0njxa.medium.com\/profiling-traffic-cerberus-ex-amnesia-3758faba4385\" target=\"_blank\" rel=\"noopener\">for violating the foundations of darknet boards<\/a> the place their companies are marketed.<\/p>\n<p>This part offers solely a high-level overview of Amadey, as deep technical evaluation has already been revealed within the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/posts\/teethador_swisscom-tdr-threat-brief-unmasking-amadey-activity-7403675667952844800-tFQL\/\" target=\"_blank\" rel=\"noopener\">Swisscom report<\/a>.<\/p>\n<h3>C&amp;C communications<\/h3>\n<p>Amadey communicates with its C&amp;C server over HTTP utilizing POST requests. At a excessive degree, communication follows a three-stage lifecycle:<\/p>\n<ul>\n<li><strong>Preliminary beacon<\/strong> \u2013 the bot sends a minimal <span style=\"font-family: courier new, courier, monospace;\">st=s<\/span> HTTP POST request to the C&amp;C server. The server responds with a sleep interval, for instance <span style=\"font-family: courier new, courier, monospace;\"><c>10<d\/><\/c><\/span>, instructing the bot to attend 10 minutes between subsequent check-ins.<\/li>\n<li><strong>Registration<\/strong> \u2013 the bot transmits RC4-encrypted system info encoded as a flat key-value string. This information consists of the working system model, username, PC identify, put in antivirus product, administrative privileges, <span style=\"font-family: courier new, courier, monospace;\">sd<\/span> worth, and different host info. Notably, the RC4 key itself isn&#8217;t transmitted over the community. Based mostly on our telemetry, no server was noticed serving duties for multiple RC4 key at a time, suggesting that every pattern should talk with a C&amp;C server that already is aware of and expects that precise RC4 key. The server responds with a activity listing.<\/li>\n<li><strong>Tasking<\/strong> \u2013 duties are delivered as structured command strings delimited by <span style=\"font-family: courier new, courier, monospace;\"><c\/><\/span> and <span style=\"font-family: courier new, courier, monospace;\"><d\/><\/span> tags with particular person instructions separated by <span style=\"font-family: courier new, courier, monospace;\">#<\/span> characters, as proven in Determine 4. Every activity encodes a command kind, similar to downloading and executing an EXE, beginning VNC, or operating a stealer plugin. Duties additionally embrace parameters similar to a privilege escalation flag, goal listing, and payload URL.<\/li>\n<\/ul>\n<p>Every activity has its personal processing logic, starting from easy download-and-execute instructions to extra complicated execution of hVNC or proxy elements. The internal workings have been documented in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/posts\/teethador_swisscom-tdr-threat-brief-unmasking-amadey-activity-7403675667952844800-tFQL\/\">earlier technical reporting<\/a>.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 4. Amadey C&amp;C communications with highlighted list of delimited encrypted tasks\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-4.png\" alt=\"Figure 4. Amadey C&amp;C communications with highlighted list of delimited encrypted tasks\" width=\"\" height=\"\"\/><figcaption><em>Determine 4. Amadey C&amp;C communications with highlighted listing of delimited encrypted duties<\/em><\/figcaption><\/figure>\n<h3>Clustering<a rel=\"nofollow\" target=\"_blank\" id=\"Clustering\"\/><\/h3>\n<p>When monitoring MaaS malware, a key problem is discovering a dependable option to group samples belonging to the identical risk actor. Understanding the enterprise mannequin and the distribution of community infrastructure is thus important for profitable disruption, as a result of it permits defenders and legislation enforcement to determine the crucial factors the place motion may have the best affect. On this part, we clarify our methodology.<\/p>\n<p>Amadey samples include three key hardcoded configuration values:<\/p>\n<ul>\n<li>C&amp;C URLs,<\/li>\n<li>RC4 keys used for C&amp;C communications, and<\/li>\n<li>the <span style=\"font-family: courier new, courier, monospace;\">sd<\/span> worth transmitted in the course of the preliminary C&amp;C handshake.<\/li>\n<\/ul>\n<p>Over the course of our monitoring, we seen that Amadey C&amp;C URLs comply with a constant sample:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">http(s)?:\/\/<c>\/<random_path>\/index.php<\/random_path><\/c><\/span><\/p>\n<p>Additional, the identical <span style=\"font-family: courier new, courier, monospace;\"><random_path\/><\/span> URL half was used with completely different C&amp;C servers (see Determine 5). As this worth seems to be a random string, seeing it tied to a number of C&amp;C servers over time appeared like a robust indicator that the C&amp;C servers are operated as a part of the identical cluster. Subsequently, we additional decomposed the C&amp;C URL into these two components: the IP handle or area and the URL <span style=\"font-family: courier new, courier, monospace;\"><random_path\/><\/span>.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 5. Examples of &lt;random_path&gt; identifiers in Amadey C&amp;C server URLs\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-5.png\" alt=\"Figure 5. Examples of random_path identifiers in Amadey C&amp;C server URLs\" width=\"\" height=\"\"\/><figcaption><em>Determine 5. Examples of <\/em><span style=\"font-family: courier new, courier, monospace;\"><random_path\/><\/span><em> identifiers in Amadey C&amp;C server URLs<\/em><\/figcaption><\/figure>\n<p>Utilizing values from the samples\u2019 configuration, mixed with our understanding of their goal, we leveraged graph modeling to realize insights into the construction of the Amadey ecosystem. On first look at Determine 6, we clearly see that, certainly, there isn&#8217;t a shared infrastructure, however relatively a number of smaller sub-botnets with one clearly dominating. We dive deeper into that largest cluster within the subsequent part.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 6. Amadey affiliate clustering based on ESET telemetry\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-6.png\" alt=\"Figure 6. Amadey affiliate clustering based on ESET telemetry\" width=\"\" height=\"\"\/><figcaption><em>Determine 6. Amadey affiliate clustering primarily based on ESET telemetry<\/em><\/figcaption><\/figure>\n<p>To conclude, the principle takeaways are:<\/p>\n<ol>\n<li>We recognized a complete of <strong>53 distinctive clusters <\/strong>contained in the Amadey ecosystem.<\/li>\n<li>Every <span style=\"font-family: courier new, courier, monospace;\">sd<\/span> worth is tied to precisely one RC4 key.<\/li>\n<li>RC4 keys are probably a helpful affiliate identifier, as rebuilds protect the important thing whereas altering the <span style=\"font-family: courier new, courier, monospace;\">sd<\/span> worth.<\/li>\n<li>The C&amp;C URL <span style=\"font-family: courier new, courier, monospace;\"><random_path\/><\/span> half is often reused when rotating C&amp;C servers, serving as dependable proof of such C&amp;C servers belonging to the identical cluster.<\/li>\n<\/ol>\n<h3>The most important Amadey botnet cluster<\/h3>\n<p>One cluster stands out as the biggest, and it contributed practically 34% of all processed Amadey samples. This cluster was additionally the one one energetic all through the whole analyzed time interval, as represented in our timeline in Determine 7.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 7. Activity of the 10 largest Amadey botnets (largest at top)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-7.png\" alt=\"Figure 7. Activity of the 10 largest Amadey botnets (largest at top)\" width=\"\" height=\"\"\/><figcaption><em>Determine 7. Exercise of the ten largest Amadey botnets (largest at prime)<\/em><\/figcaption><\/figure>\n<p>The most important botnet additionally dominated within the common variety of payloads distributed to victims per execution. Based mostly on our clustering methodology, Amadey samples belonging to the biggest botnet delivered, on common, round 14 payloads to each sufferer concurrently (Determine 8).<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 8. Top five botnets based on the average number of payloads distributed per Amadey execution\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-8.png\" alt=\"Figure 8. Top five botnets based on the average number of payloads distributed per Amadey execution\" width=\"\" height=\"\"\/><figcaption><em>Determine 8. High 5 botnets primarily based on the common variety of payloads distributed per Amadey execution<\/em><\/figcaption><\/figure>\n<p>The vary and variety of distributed malware households was broad, from infostealers and RATs to malware filled with complicated code protectors. Determine 9 offers an perception into the payloads we detected being delivered all through the monitoring interval.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 9. Payload distribution of the largest Amadey botnet\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-9.png\" alt=\"Figure 9. Payload distribution of the largest Amadey botnet\" width=\"\" height=\"\"\/><figcaption><em>Determine 9. Payload distribution of the biggest Amadey botnet<\/em><\/figcaption><\/figure>\n<p>Moreover, ESET researchers had been capable of receive proof that many occasions, a number of Lumma Stealer samples had been delivered to a single sufferer, every attributed to a distinct affiliate (see our earlier <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-takes-part-global-operation-disrupt-lumma-stealer\/\"><em style=\"mso-bidi-font-style: normal;\">Lumma Stealer analysis<\/em><\/a>). This ends in a number of Lumma Stealer associates ending up with the identical stolen information. This commentary leads us to conclude that the risk actors controlling this largest cluster probably ran their very own pay-per-install (PPI) mannequin, additional monetizing their bots.<\/p>\n<h2>Stealc<\/h2>\n<p>In distinction to Amadey, Stealc is a typical consultant of an infostealer. It targets a broad vary of knowledge sources, together with credentials saved by net browsers, e mail purchasers, FTP purchasers, gaming platforms, cryptocurrency pockets information, and browser extensions.<\/p>\n<p>Stealc was launched on a darknet discussion board in February 2023, and we began monitoring it shortly thereafter. Our telemetry detection charge, proven in Determine 10, signifies that Stealc was distributed globally with no particular regional focus. The best detection charges had been noticed in america, Poland, and Italy.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 10. Distribution of Stealc \u2013 detection heatmap (2025\u2013present)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-10.png\" alt=\"Figure 10. Distribution of Stealc \u2013 detection heatmap (2025\u2013present)\" width=\"\" height=\"\"\/><figcaption><em>Determine 10. Distribution of Stealc \u2013 detection heatmap (2025\u2013current)<\/em><\/figcaption><\/figure>\n<p>Stealc is marketed by a risk actor utilizing the moniker plymouth. The operators had been actively sustaining Stealc; every time a brand new model was launched, they disclosed launch notes in a darknet discussion board put up. There have been 37 such releases prior to now three years. Stealc is bought as a month-to-month subscription, with pricing that has developed solely barely:<\/p>\n<ul>\n<li>US$300 monthly<\/li>\n<li>US$700 for 3 months<\/li>\n<li>US$1,000 for six months<\/li>\n<\/ul>\n<p>In March 2025, Stealc acquired a serious architectural replace with model 2, introducing important adjustments to the community protocol and configuration construction and \u2013 since then \u2013 this model has dominated in our telemetry. By June 2026, it had reached model 2.22.1, as proven in Determine 11.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 11. Stealc version timeline\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-11.png\" alt=\"Figure 11. Stealc version timeline\" width=\"\" height=\"\"\/><figcaption><em>Determine 11. Stealc model timeline<\/em><\/figcaption><\/figure>\n<p>Apart from its most important targets, Stealc features a configurable file grabber that permits associates to specify customized patterns defining information to exfiltrate from compromised machines. Its C&amp;C communications and embedded strings are protected by RC4 encryption with per-build keys.<\/p>\n<p>Stealc doesn&#8217;t depend on a single, standardized distribution technique \u2013 every affiliate is chargeable for its personal supply mechanisms. Nevertheless, much like Amadey, our telemetry signifies that sure vectors persistently stand out \u2013 notably trojanized software program installers and established malware loaders (like Amadey).<\/p>\n<h3>Technical overview<\/h3>\n<p>An in depth technical evaluation of Stealc v2 has already been revealed by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/lumma-labs.com\/autopsy-of-a-failed-stealer-stealc-v2-a4e32da04396\" target=\"_blank\" rel=\"noopener\">Lumma-Labs<\/a>. On this part, we give attention to the properties usable for clustering.<\/p>\n<p>Present variations of Stealc embed two distinct RC4 keys per pattern:<\/p>\n<ul>\n<li>one to decrypt obfuscated strings at runtime, and<\/li>\n<li>a second one to encrypt C&amp;C community communications.<\/li>\n<\/ul>\n<p>Along with the 2 RC4 keys, we&#8217;ve got been extracting the <span style=\"font-family: courier new, courier, monospace;\">construct<\/span> identifier from Stealc samples. This worth represents a person Stealc marketing campaign, and in contrast to different strings it&#8217;s not protected within the binary. The worth is essential as a result of it&#8217;s transmitted as a part of the C&amp;C handshake (see Determine 12).<\/p>\n<p>The C&amp;C server handle and URL path used for communications are each saved among the many RC4-encrypted strings and have been extracted as a part of our automated configuration unpacking pipeline.<\/p>\n<h3>C&amp;C communications<\/h3>\n<p>Stealc communicates with its C&amp;C server over HTTP utilizing RC4-encrypted JSON objects. The preliminary request despatched to the C&amp;C comprises three values:<\/p>\n<ul>\n<li>a construct identifier (<span style=\"font-family: courier new, courier, monospace;\">construct<\/span>),<\/li>\n<li>a fingerprint of the compromised machine (<span style=\"font-family: courier new, courier, monospace;\">hwid<\/span>), and<\/li>\n<li>the request kind (this preliminary request is of the kind <span style=\"font-family: courier new, courier, monospace;\">create<\/span>).<\/li>\n<\/ul>\n<p>The machine fingerprint is derived from the system\u2019s quantity serial quantity and formatted as a UUIDv4 string. An instance JSON object for this preliminary request is proven in Determine 12.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 12. Example of a create request issued by Stealc\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-12.png\" alt=\"Figure 12. Example of a create request issued by Stealc\" width=\"\" height=\"\"\/><figcaption><em>Determine 12. Instance of a <\/em><span style=\"font-family: courier new, courier, monospace;\">create<\/span><em> request issued by Stealc<\/em><\/figcaption><\/figure>\n<p>The C&amp;C server responds with a posh JSON object that defines what options Stealc ought to carry out. Alongside that, the response comprises a randomly generated <span style=\"font-family: courier new, courier, monospace;\">access_token<\/span> worth that acts as a session key and must be utilized in all subsequent requests, in any other case they&#8217;re refused by the server. Apart from the complicated definitions of targets, the JSON object additionally defines whether or not to take a screenshot, self-destruct when completed, or obtain and execute a further payload afterwards. An instance of response JSON object is proven in Determine 13.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 13. Decrypted Stealc configuration from C&amp;C server\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-13.png\" alt=\"Figure 13. Decrypted Stealc configuration from C&amp;C server\" width=\"\" height=\"\"\/><figcaption><em>Determine 13. Decrypted Stealc configuration from C&amp;C server<\/em><\/figcaption><\/figure>\n<p>Every server response additionally comprises a randomly generated key-value pair on the very starting \u2013 neither hexadecimal string is ever reused in subsequent C&amp;C communications. In response to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/i-stealc-you-tracking-rapid-changes-stealc\">Zscaler analysis<\/a>, this prevents static detection signatures on RC4-encrypted site visitors, even when the identical encryption secret&#8217;s used repeatedly. In Determine 13 the randomly generated nonce is <span style=\"font-family: courier new, courier, monospace;\">&#8220;bf66e52&#8221;<\/span>: <span style=\"font-family: courier new, courier, monospace;\">&#8220;03030ac3e9a8cebf&#8221;<\/span>.<\/p>\n<p>After the preliminary registration, Stealc makes use of three extra operation varieties with self-explanatory names to carry out its performance:<\/p>\n<ul>\n<li><span style=\"font-family: courier new, courier, monospace;\">upload_file<\/span> \u2013 exfiltrate collected information,<\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">loader<\/span> \u2013 fetch and execute a follow-on payload, and<\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">completed<\/span> \u2013 sign completion.<\/li>\n<\/ul>\n<h3>Clustering<\/h3>\n<p>As talked about, in contrast to Lumma Stealer\u2019s, Stealc operators provide their associates no shared infrastructure. Just like our clustering strategy for Amadey, we utilized graph modeling to values extracted from Stealc configurations, mixed with our understanding of their goal, to raised comprehend the construction of the Stealc ecosystem. We ended up with a graph exhibiting that Stealc is certainly fractured into many small clusters (see Determine 14). Every cluster is centered round a small variety of C&amp;C servers (typically only one) and usually tied to just a few <span style=\"font-family: courier new, courier, monospace;\">construct<\/span> IDs or C&amp;C URL paths. Disrupting such infrastructure is due to this fact a difficult activity because of the lack of a weak level. Total, we recognized a complete of <strong>73 distinct clusters<\/strong> (see Determine 14) working Stealc since March 2025.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 14. Stealc affiliate clustering based on ESET telemetry\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/06-26\/operation-endgame\/figure-14.png\" alt=\"Figure 14. Stealc affiliate clustering based on ESET telemetry\" width=\"\" height=\"\"\/><figcaption><em>Determine 14. Stealc affiliate clustering primarily based on ESET telemetry<\/em><\/figcaption><\/figure>\n<h2>Conclusion<\/h2>\n<p>For world disruption operations similar to Operation Endgame in opposition to Amadey and Stealc, long-term automated monitoring of malware is critical. This blogpost presents info collected in that method but additionally offers particulars on the particular MaaS enterprise mannequin behind every household and the way that interprets into typically fragmented community infrastructure, paperwork their key static identifiers and C&amp;C communication protocols, and descriptions how ESET researchers helped to determine crucial factors for the disruption. Our risk intelligence on each Amadey and Stealc, mixed with information shared by our companions, offered a robust basis for each the disruption operation and legislation enforcement efforts.<\/p>\n<p>Operation Endgame aimed to grab or render inoperative all recognized Amadey and Stealc C&amp;C servers, straight disrupting the infrastructure relied upon by each MaaS choices\u2019 associates. ESET will proceed to watch each households and monitor any makes an attempt to rebuild operational infrastructure following this disruption.<\/p>\n<h2>IoCs<\/h2>\n<p>A complete listing of indicators of compromise (IoCs) and samples will be present in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/eset\/malware-ioc\/tree\/master\/amadey_stealc\" target=\"_blank\" rel=\"noopener\">our GitHub repository<\/a>.<\/p>\n<h3>Information<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><strong>SHA\u20111<\/strong><\/td>\n<td style=\"width: 197.438px;\" width=\"197\"><strong>Filename<\/strong><\/td>\n<td style=\"width: 180.359px;\" width=\"217\"><strong>Detection<\/strong><\/td>\n<td style=\"width: 139.1094px;\" width=\"114\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">11A42EF076686CB27BA2<wbr\/>C8845301943652A5AADC<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\"><span style=\"font-family: courier new, courier, monospace;\">KB.14.804.84<wbr\/>07.exe<\/span><\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win64\/Stealc.A<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Stealc infostealer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">32D0C3300825B0BB991C<wbr\/>4A8F1E6244F0AD2DA989<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\"><span style=\"font-family: courier new, courier, monospace;\">yinkaroj.exe<\/span><\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win64\/Stealc.A<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Stealc infostealer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">5F3F99B14243404C7CF5<wbr\/>7B40BB101244CCE394BF<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\"><span style=\"font-family: courier new, courier, monospace;\">MusNotificat<wbr\/>ion.exe<\/span><\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win64\/Stealc.B<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Stealc infostealer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">B4101027BF2F1261402B<wbr\/>F6318C6EB016CE249037<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\"><span style=\"font-family: courier new, courier, monospace;\">Patch.exe<\/span><\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win32\/Spy.Agent.QOL<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Stealc infostealer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">F61E3A643F2417E1A1AB<wbr\/>2C83BBDBFC8A7CB96756<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\"><span style=\"font-family: courier new, courier, monospace;\">VeloTeam_x32<wbr\/>.exe<\/span><\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win32\/Spy.Agent.QOL<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Stealc infostealer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">09002D4668A778853E8D<wbr\/>A5C488C6E421C0628357<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\">N\/A<\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win32\/TrojanDownloa<wbr\/>der.Amadey.A<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Amadey.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">87867AD29E621BF9EBF5<wbr\/>7E1757F75090842458BE<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\">N\/A<\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win32\/TrojanDownloa<wbr\/>der.Amadey.A<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Amadey.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">38D744543B2051E6F749<wbr\/>AF171B5EF8D6DF8AAC7B<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\">N\/A<\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win64\/TrojanDownloa<wbr\/>der.Amadey.A<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Amadey.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">C0E178D26E1E613985A9C<wbr\/>67E649D71D54642E0EED<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\">N\/A<\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win64\/TrojanDownloa<wbr\/>der.Amadey.A<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Amadey.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 220.906px;\" width=\"1139\"><span style=\"font-family: courier new, courier, monospace;\">FF8D2AFD9D7F0A822092<wbr\/>FEE34CA55D1A3542F7ED<\/span><\/td>\n<td style=\"width: 197.438px;\" width=\"197\">N\/A<\/td>\n<td style=\"width: 180.359px;\" width=\"217\">Win32\/TrojanDownloa<wbr\/>der.Amadey.A<\/td>\n<td style=\"width: 139.1094px;\" width=\"114\">Amadey.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Community<\/h3>\n<p><span style=\"font-size: medium; font-weight: 400;\"><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"156\"><strong>IP<\/strong><\/td>\n<td width=\"100\"><strong>Area<\/strong><\/td>\n<td width=\"181\"><strong>Internet hosting supplier<\/strong><\/td>\n<td width=\"80\"><strong>First seen<\/strong><\/td>\n<td width=\"156\"><strong>Particulars<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">62.60.226[.]159<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">FEMO IT SOLUTIONS LIMITED<\/td>\n<td width=\"80\">2026\u201104\u201113<\/td>\n<td width=\"156\">Amadey C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">64.188.91[.]237<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">Hurricane Electrical LLC<\/td>\n<td width=\"80\">2026\u201103\u201119<\/td>\n<td width=\"156\">Stealc C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">94.154.35[.]25<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">Artem Sevastyanov<\/td>\n<td width=\"80\">2026\u201103\u201126<\/td>\n<td width=\"156\">Amadey C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">95.85.238[.]4<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">DATAMAT CZ s.r.o.<\/td>\n<td width=\"80\">2026\u201104\u201109<\/td>\n<td width=\"156\">Stealc C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">176.111.174[.]140<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">RU-NUBES-20220530<\/td>\n<td width=\"80\">2026\u201103\u201104<\/td>\n<td width=\"156\">Amadey C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">176.124.199[.]207<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">AEZA INTERNATIONAL LTD<\/td>\n<td width=\"80\">2026\u201103\u201131<\/td>\n<td width=\"156\">Stealc C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">188.114.96[.]1<\/span><\/td>\n<td width=\"100\"><span style=\"font-family: courier new, courier, monospace;\">mi.overlapsno<wbr\/>wbound[.]com<\/span><\/td>\n<td width=\"181\">Cloudflare, Inc.<\/td>\n<td width=\"80\">2026\u201104\u201102<\/td>\n<td width=\"156\">Amadey C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">193.156.1[.]16<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">RU-PROTON66-20191118<\/td>\n<td width=\"80\">2026\u201102\u201124<\/td>\n<td width=\"156\">Amadey C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">194.26.192[.]191<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">1337 Companies GmbH<\/td>\n<td width=\"80\">2026\u201102\u201120<\/td>\n<td width=\"156\">Stealc C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"156\"><span style=\"font-family: courier new, courier, monospace;\">196.251.107[.]130<\/span><\/td>\n<td width=\"100\">N\/A<\/td>\n<td width=\"181\">NTT America, Inc.<\/td>\n<td width=\"80\">2026\u201104\u201117<\/td>\n<td width=\"156\">Stealc C&amp;C server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/span><\/p>\n<h2>MITRE ATT&amp;CK strategies<\/h2>\n<p>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\" target=\"_blank\" rel=\"noopener\">model 19<\/a> of the MITRE ATT&amp;CK framework.<\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>Tactic<\/strong><\/td>\n<td width=\"113\"><strong>ID<\/strong><\/td>\n<td width=\"151\"><strong>Title<\/strong><\/td>\n<td width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Useful resource Improvement<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1583\/004\" target=\"_BLANK\">T1583.004<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Server<\/td>\n<td width=\"265\">Amadey associates purchase servers to host C&amp;C panels and help Amadey operations.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1587\/001\" target=\"_BLANK\">T1587.001<\/a><\/td>\n<td width=\"151\">Develop Capabilities: Malware<\/td>\n<td width=\"265\">Amadey operators actively develop their malware and instruments to help their monetization efforts.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1588\/001\" target=\"_BLANK\">T1588.001<\/a><\/td>\n<td width=\"151\">Get hold of Capabilities: Malware<\/td>\n<td width=\"265\">Amadey associates typically purchase extra malware to be distributed to a compromised system.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1608\/001\" target=\"_BLANK\">T1608.001<\/a><\/td>\n<td width=\"151\">Stage Capabilities: Add Malware<\/td>\n<td width=\"265\">Amadey and Stealc associates can add acquired malware to their infrastructure or third-party net companies to distribute it.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Preliminary Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1195\" target=\"_BLANK\">T1195<\/a><\/td>\n<td width=\"151\">Provide Chain Compromise<\/td>\n<td width=\"265\">Amadey and Stealc are distributed by means of trojanized, cracked software program installers.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Execution<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1059\/003\" target=\"_BLANK\">T1059.003<\/a><\/td>\n<td width=\"151\">Command and Scripting Interpreter: Home windows Command Shell<\/td>\n<td width=\"265\">Amadey makes use of <span style=\"font-family: courier new, courier, monospace;\">cmd.exe<\/span> to help its operation and might execute arbitrary CMD script information.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1106\" target=\"_BLANK\">T1106<\/a><\/td>\n<td width=\"151\">Native API<\/td>\n<td width=\"265\">Amadey makes use of numerous Home windows API features all through its execution.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1129\" target=\"_BLANK\">T1129<\/a><\/td>\n<td width=\"151\">Shared Modules<\/td>\n<td width=\"265\">Amadey can load extra credential stealer and clipper plugins to boost its capabilities.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1204\/002\" target=\"_BLANK\">T1204.002<\/a><\/td>\n<td width=\"151\">Person Execution: Malicious File<\/td>\n<td width=\"265\">Amadey and Stealc are distributed as a PE file to be executed by the sufferer.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Persistence<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1136\/001\" target=\"_BLANK\">T1136.001<\/a><\/td>\n<td width=\"151\">Create Account: Native Account<\/td>\n<td width=\"265\">Amadey can create an administrative account on a compromised system.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1547\/001\" target=\"_BLANK\">T1547.001<\/a><\/td>\n<td width=\"151\">Boot or Logon Autostart Execution: Registry Run Keys \/ Startup Folder<\/td>\n<td width=\"265\">Amadey can set up persistence for newly downloaded malware by making a registry Run key.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"8\" width=\"113\"><strong>Stealth<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1027\/015\" target=\"_BLANK\">T1027.015<\/a><\/td>\n<td width=\"151\">Obfuscated Information or Info: Compression<\/td>\n<td width=\"265\">Amadey can obtain, decompress, and execute payloads delivered in ZIP archives.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1055\/002\" target=\"_BLANK\">T1055.002<\/a><\/td>\n<td width=\"151\">Course of Injection: Transportable Executable Injection<\/td>\n<td width=\"265\">Amadey can inject a downloaded payload into its little one course of.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1480\" target=\"_BLANK\">T1480<\/a><\/td>\n<td width=\"151\">Execution Guardrails<\/td>\n<td width=\"265\">Amadey and Stealc verify the keyboard structure and abort execution if it matches a CIS nation.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1140\" target=\"_BLANK\">T1140<\/a><\/td>\n<td width=\"151\">Deobfuscate\/Decode Information or Info<\/td>\n<td width=\"265\">Amadey and Stealc encrypt their strings, community site visitors, and downloaded payloads.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1218\/007\" target=\"_BLANK\">T1218.007<\/a><\/td>\n<td width=\"151\">Signed Binary Proxy Execution: Msiexec<\/td>\n<td width=\"265\">Amadey can obtain and execute a further payload distributed in an MSI bundle.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1218\/011\" target=\"_BLANK\">T1218.011<\/a><\/td>\n<td width=\"151\">Signed Binary Proxy Execution: Rundll32<\/td>\n<td width=\"265\">Amadey can obtain and cargo a further DLL file utilizing <span style=\"font-family: courier new, courier, monospace;\">rundll32.exe<\/span>.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1027\" target=\"_BLANK\">T1027<\/a><\/td>\n<td width=\"151\">Obfuscated Information or Info<\/td>\n<td width=\"265\">The vast majority of strings in Stealc (C&amp;C addresses, URLs, configuration parameters) are RC4 encrypted inside the binary.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1036\" target=\"_BLANK\">T1036<\/a><\/td>\n<td width=\"151\">Masquerading<\/td>\n<td width=\"265\">Stealc masquerades as a reputable binary.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"6\" width=\"113\"><strong>Credential Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1552\/001\" target=\"_BLANK\">T1552.001<\/a><\/td>\n<td width=\"151\">Unsecured Credentials: Credentials In Information<\/td>\n<td width=\"265\">Amadey and Stealc can harvest credentials from numerous purposes, similar to crypto wallets and FTP and messaging purchasers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1552\/002\" target=\"_BLANK\">T1552.002<\/a><\/td>\n<td width=\"151\">Unsecured Credentials: Credentials in Registry<\/td>\n<td width=\"265\">Amadey can harvest software credentials saved within the registry, similar to these from Outlook and the WinSCP shopper.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1555\/003\" target=\"_BLANK\">T1555.003<\/a><\/td>\n<td width=\"151\">Credentials from Password Shops: Credentials from Internet Browsers<\/td>\n<td width=\"265\">Stealc and Amadey can harvest credentials from numerous Internet Browsers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1528\" target=\"_BLANK\">T1528<\/a><\/td>\n<td width=\"151\">Steal Software Entry Token<\/td>\n<td width=\"265\">Stealc targets software tokens (e.g., crypto wallets, messaging apps).<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1539\" target=\"_BLANK\">T1539<\/a><\/td>\n<td width=\"151\">Steal Internet Session Cookie<\/td>\n<td width=\"265\">Stealc harvests browser cookies alongside credentials.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1555\" target=\"_BLANK\">T1555<\/a><\/td>\n<td width=\"151\">Credentials from Password Shops<\/td>\n<td width=\"265\">Stealc targets browser-stored credentials (passwords, autofill information).<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"8\" width=\"113\"><strong>Discovery<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1012\" target=\"_BLANK\">T1012<\/a><\/td>\n<td width=\"151\">Question Registry<\/td>\n<td width=\"265\">Amadey reads numerous information from the registry, similar to information to reap, Home windows model, and keyboard structure.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1016\" target=\"_BLANK\">T1016<\/a><\/td>\n<td width=\"151\">System Community Configuration Discovery<\/td>\n<td width=\"265\">Amadey and Stealc ship details about the compromised system\u2019s community setup to their C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1033\" target=\"_BLANK\">T1033<\/a><\/td>\n<td width=\"151\">System Proprietor\/Person Discovery<\/td>\n<td width=\"265\">Amadey and Stealc ship the sufferer\u2019s username to their C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1057\" target=\"_BLANK\">T1057<\/a><\/td>\n<td width=\"151\">Course of Discovery<\/td>\n<td width=\"265\">Amadey\u2019s credential stealer plugin enumerates operating processes to determine focused purposes. Stealc additionally enumerates operating processes throughout its preliminary execution stage.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1082\" target=\"_BLANK\">T1082<\/a><\/td>\n<td width=\"151\">System Info Discovery<\/td>\n<td width=\"265\">Amadey and Stealc ship numerous system info, such because the Home windows model, the pc identify, and different metadata to their C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1083\" target=\"_BLANK\">T1083<\/a><\/td>\n<td width=\"151\">File and Listing Discovery<\/td>\n<td width=\"265\">Amadey and Stealc search the file system to find fascinating information to reap, safety merchandise, and different artifacts of curiosity.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1518\/001\" target=\"_BLANK\">T1518.001<\/a><\/td>\n<td width=\"151\">Software program Discovery: Safety Software program Discovery<\/td>\n<td width=\"265\">Amadey checks the system for a set of safety merchandise and stories these put in to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1614\/001\" target=\"_BLANK\">T1614.001<\/a><\/td>\n<td width=\"151\">System Location Discovery: System Language Discovery<\/td>\n<td width=\"265\">Amadey and Stealc verify the system keyboard structure\/locale to implement CIS-country execution blocks.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Assortment<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1113\" target=\"_BLANK\">T1113<\/a><\/td>\n<td width=\"151\">Display screen Seize<\/td>\n<td width=\"265\">Amadey and Stealc can seize a screenshot when instructed to take action.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1119\" target=\"_BLANK\">T1119<\/a><\/td>\n<td width=\"151\">Automated Assortment<\/td>\n<td width=\"265\">Amadey makes use of its credential stealer plugin to gather and exfiltrate credentials from numerous purposes. Stealc\u2019s credential assortment is absolutely automated and policy-driven through the C&amp;C-supplied configuration.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1005\" target=\"_BLANK\">T1005<\/a><\/td>\n<td width=\"151\">Information from Native System<\/td>\n<td width=\"265\">Stealc collects information matching operator-defined patterns from the native file system through the configurable file grabber.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"5\" width=\"113\"><strong>Command and Management<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1008\" target=\"_BLANK\">T1008<\/a><\/td>\n<td width=\"151\">Fallback Channels<\/td>\n<td width=\"265\">Amadey\u2019s configuration might include as much as three C&amp;C servers in case the first one turns into inaccessible.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1071\/001\" target=\"_BLANK\">T1071.001<\/a><\/td>\n<td width=\"151\">Software Layer Protocol: Internet Protocols<\/td>\n<td width=\"265\">Amadey communicates with its C&amp;C server over HTTP. Stealc communicates over HTTP(S) utilizing a JSON-based protocol.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1132\/001\" target=\"_BLANK\">T1132.001<\/a><\/td>\n<td width=\"151\">Information Encoding: Customary Encoding<\/td>\n<td width=\"265\">Amadey makes use of hexadecimal and base64 encodings for transferred information. Stealc makes use of base64 for exfiltrated information on prime of RC4 encryption.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1219\/002\" target=\"_BLANK\">T1219.002<\/a><\/td>\n<td width=\"151\">Distant Entry Software program: Distant Desktop Software program<\/td>\n<td width=\"265\">Amadey helps distant management of compromised techniques through its VNC plugin or by means of an RDP connection.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1573\/001\" target=\"_BLANK\">T1573.001<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Symmetric Cryptography<\/td>\n<td width=\"265\">Amadey and Stealc use the RC4 cipher for encrypting C&amp;C communications.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1020\" target=\"_BLANK\">T1020<\/a><\/td>\n<td width=\"151\">Automated Exfiltration<\/td>\n<td width=\"265\">Amadey and Stealc exfiltrate collected information to their C&amp;Cs absolutely robotically with out operator interplay.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1041\" target=\"_BLANK\">T1041<\/a><\/td>\n<td width=\"151\">Exfiltration Over C2 Channel<\/td>\n<td width=\"265\">Amadey and Stealc exfiltrate collected information to their C&amp;C servers.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=eset-takes-part-operation-endgame-disrupt-amadey-stealc&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/eti-eset-threat-intelligence.png\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A yr in the past, ESET Analysis was a part of two main operations that disrupted a number of the main cybercriminal operations on the time, Lumma Stealer and Danabot. Extra not too long ago, our researchers are as soon as once more collaborating with personal companions and legislation enforcement, however this time taking purpose [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16089,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[9546,3080,2735,679,2130,668,7959,595],"class_list":["post-16087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-amadey","tag-disrupt","tag-endgame","tag-eset","tag-operation","tag-part","tag-stealc","tag-takes"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16087"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16087\/revisions"}],"predecessor-version":[{"id":16088,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16087\/revisions\/16088"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/16089"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-25 20:31:47 UTC -->