ESET Details Its Role in Operation Endgame Disruption of Amadey and Stealc

· Original article ↗

Summary

ESET shared malware analysis, indicators, and affiliate-clustering data with Operation Endgame, which targeted about 50 domains and nearly 200 active command-and-control IPs used by Amadey and Stealc.

Key points

  • ESET contributed technical analyses, statistics, C&C server data, encryption keys, and campaign and build identifiers to the coordinated operation.
  • Operation Endgame targeted around 50 domains and nearly 200 active IP addresses used as C&C servers for Amadey or Stealc.
  • Amadey is a modular loader that can deliver additional malware; Stealc is an infostealer targeting credentials, cookies, cryptocurrency wallets, and files.
  • Both malware families are distributed through affiliates who operate their own infrastructure, complicating disruption efforts.
  • ESET identified 53 Amadey clusters and 73 Stealc clusters using malware configuration values and C&C infrastructure data.
  • Common delivery methods included fake software updates, cracked installers, and other malware loaders.
  • ESET says it will continue monitoring the malware families for attempts to rebuild infrastructure after the disruption.

Article Details

Attack Vectors
  • Amadey and Stealc were distributed through fake software updates, cracked or trojanized software installers, and third-party malware loaders.
  • Amadey delivers additional malware to compromised systems; Stealc can fetch and execute follow-on payloads.
  • Amadey and Stealc affiliates operate their own infrastructure, including C&C servers and administration panels.
Defensive Notes
  • ESET shared C&C server data, encryption keys, campaign and build identifiers, and statistical analysis to support Operation Endgame's disruption of Amadey and Stealc infrastructure.
  • Clustering samples using configuration values such as RC4 keys, build identifiers, and C&C URL paths can help distinguish affiliate activity and prioritize infrastructure for disruption.
  • ESET said it will continue monitoring both malware families for attempts to rebuild operational infrastructure.

Indicators of compromise

TypeIndicatorContext
DOMAINmi[.]overlapsnowbound[.]comDomain listed as an Amadey C&C server.
IPV4176[.]111[.]174[.]140Amadey C&C server listed as a network indicator.
IPV4176[.]124[.]199[.]207Stealc C&C server listed as a network indicator.
IPV4188[.]114[.]96[.]1Amadey C&C server listed as a network indicator.
IPV4193[.]156[.]1[.]16Amadey C&C server listed as a network indicator.
IPV4194[.]26[.]192[.]191Stealc C&C server listed as a network indicator.
IPV4196[.]251[.]107[.]130Stealc C&C server listed as a network indicator.
IPV462[.]60[.]226[.]159Amadey C&C server listed as a network indicator.
IPV464[.]188[.]91[.]237Stealc C&C server listed as a network indicator.
IPV494[.]154[.]35[.]25Amadey C&C server listed as a network indicator.
IPV495[.]85[.]238[.]4Stealc C&C server listed as a network indicator.
SHA109002d4668a778853e8da5c488c6e421c0628357SHA-1 hash of an Amadey sample.
SHA111a42ef076686cb27ba2c8845301943652a5aadcSHA-1 hash of a sample identified as the Stealc infostealer.
SHA132d0c3300825b0bb991c4a8f1e6244f0ad2da989SHA-1 hash of a sample identified as the Stealc infostealer.
SHA138d744543b2051e6f749af171b5ef8d6df8aac7bSHA-1 hash of an Amadey sample.
SHA15f3f99b14243404c7cf57b40bb101244cce394bfSHA-1 hash of a sample identified as the Stealc infostealer.
SHA187867ad29e621bf9ebf57e1757f75090842458beSHA-1 hash of an Amadey sample.
SHA1b4101027bf2f1261402bf6318c6eb016ce249037SHA-1 hash of a sample identified as the Stealc infostealer.
SHA1f61e3a643f2417e1a1ab2c83bbdbfc8a7cb96756SHA-1 hash of a sample identified as the Stealc infostealer.
SHA1ff8d2afd9d7f0a822092fee34ca55d1a3542f7edSHA-1 hash of an Amadey sample.

MITRE ATT&CK

T1005 · Data from Local SystemStealc's configurable file grabber collects local files matching affiliate-defined patterns.T1008 · Fallback ChannelsAmadey samples can contain up to three C&C servers for use if the primary server becomes inaccessible.T1012 · Query RegistryAmadey reads registry data related to harvesting, Windows version, and keyboard layout.T1016 · System Network Configuration DiscoveryAmadey and Stealc send information about a compromised system's network setup to their C&C servers.T1020 · Automated ExfiltrationAmadey and Stealc can automatically exfiltrate collected data to their C&C servers.T1027 · Obfuscated Files or InformationStealc stores C&C addresses, URLs, and configuration strings encrypted with RC4 in its binary.T1027.015 · CompressionAmadey can download, decompress, and execute payloads delivered in ZIP archives.T1033 · System Owner/User DiscoveryAmadey and Stealc send the victim's username to their C&C servers.T1036 · MasqueradingStealc can masquerade as a legitimate binary.T1041 · Exfiltration Over C2 ChannelAmadey and Stealc exfiltrate collected data to their C&C servers.T1055.002 · Portable Executable InjectionAmadey can inject a downloaded payload into its child process.T1057 · Process DiscoveryAmadey's credential-stealer plugin and Stealc enumerate running processes.T1059.003 · Windows Command ShellAmadey can use cmd.exe to execute CMD script files.T1071.001 · Web ProtocolsAmadey communicates with C&C over HTTP; Stealc uses an HTTP(S), JSON-based protocol.T1082 · System Information DiscoveryAmadey and Stealc send system information, including Windows version and computer name, to their C&C servers.T1083 · File and Directory DiscoveryAmadey and Stealc search the file system for files, security products, and other artifacts of interest.T1106 · Native APIAmadey uses Windows API functions during execution.T1113 · Screen CaptureAmadey and Stealc can capture a screenshot when instructed.T1119 · Automated CollectionAmadey's plugin and Stealc's configured functionality automatically collect credentials and other data.T1129 · Shared ModulesAmadey can load credential-stealer and clipper plugins.T1132.001 · Standard EncodingAmadey uses hexadecimal and Base64 encodings for transferred data; Stealc uses Base64 for exfiltrated data in addition to RC4 encryption.T1136.001 · Local AccountAmadey can create an administrative account on a compromised system.T1140 · Deobfuscate/Decode Files or InformationAmadey and Stealc decrypt strings, network traffic, and downloaded payloads.T1195 · Supply Chain CompromiseAmadey and Stealc are distributed through trojanized or cracked software installers.T1204.002 · Malicious FileAmadey and Stealc are distributed as executable files that victims must run.T1218.007 · MsiexecAmadey can download and execute an additional payload distributed in an MSI package.T1218.011 · Rundll32Amadey can download and load an additional DLL using rundll32.exe.T1219.002 · Remote Desktop SoftwareAmadey supports remote control through its VNC plugin or an RDP connection.T1480 · Execution GuardrailsAmadey and Stealc check keyboard layout and abort execution when it matches a CIS country.T1518.001 · Security Software DiscoveryAmadey checks for installed security products and reports them to its C&C server.T1528 · Steal Application Access TokenStealc targets application access tokens, including tokens associated with cryptocurrency wallets and messaging apps.T1539 · Steal Web Session CookieStealc harvests browser cookies alongside credentials.T1547.001 · Registry Run Keys / Startup FolderAmadey can establish persistence for downloaded malware by creating a registry Run key.T1552.001 · Credentials In FilesAmadey and Stealc can harvest credentials from files, including application and wallet data.T1552.002 · Credentials in RegistryAmadey can harvest application credentials stored in the registry.T1555 · Credentials from Password StoresStealc targets browser-stored passwords and autofill data.T1555.003 · Credentials from Web BrowsersStealc and Amadey can harvest credentials stored by web browsers.T1573.001 · Symmetric CryptographyAmadey and Stealc use RC4 symmetric encryption for C&C communications.T1583.004 · ServerAmadey affiliates acquire servers to host C&C panels and support operations.T1587.001 · MalwareAmadey operators actively develop the malware and supporting capabilities.T1588.001 · MalwareAmadey affiliates acquire additional malware for distribution to compromised systems.T1608.001 · Upload MalwareAmadey and Stealc affiliates can upload acquired malware to their infrastructure or third-party web services for distribution.T1614.001 · System Language DiscoveryAmadey and Stealc check keyboard layout or locale to apply CIS-country execution blocks.

Threat Actors

Malware

Tools

Countries

Related Articles