ESET Details Its Role in Operation Endgame Disruption of Amadey and Stealc

Summary
ESET shared malware analysis, indicators, and affiliate-clustering data with Operation Endgame, which targeted about 50 domains and nearly 200 active command-and-control IPs used by Amadey and Stealc.
Key points
- ESET contributed technical analyses, statistics, C&C server data, encryption keys, and campaign and build identifiers to the coordinated operation.
- Operation Endgame targeted around 50 domains and nearly 200 active IP addresses used as C&C servers for Amadey or Stealc.
- Amadey is a modular loader that can deliver additional malware; Stealc is an infostealer targeting credentials, cookies, cryptocurrency wallets, and files.
- Both malware families are distributed through affiliates who operate their own infrastructure, complicating disruption efforts.
- ESET identified 53 Amadey clusters and 73 Stealc clusters using malware configuration values and C&C infrastructure data.
- Common delivery methods included fake software updates, cracked installers, and other malware loaders.
- ESET says it will continue monitoring the malware families for attempts to rebuild infrastructure after the disruption.
Article Details
- Attack Vectors
- Amadey and Stealc were distributed through fake software updates, cracked or trojanized software installers, and third-party malware loaders.
- Amadey delivers additional malware to compromised systems; Stealc can fetch and execute follow-on payloads.
- Amadey and Stealc affiliates operate their own infrastructure, including C&C servers and administration panels.
- Defensive Notes
- ESET shared C&C server data, encryption keys, campaign and build identifiers, and statistical analysis to support Operation Endgame's disruption of Amadey and Stealc infrastructure.
- Clustering samples using configuration values such as RC4 keys, build identifiers, and C&C URL paths can help distinguish affiliate activity and prioritize infrastructure for disruption.
- ESET said it will continue monitoring both malware families for attempts to rebuild operational infrastructure.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | mi[.]overlapsnowbound[.]com | Domain listed as an Amadey C&C server. |
| IPV4 | 176[.]111[.]174[.]140 | Amadey C&C server listed as a network indicator. |
| IPV4 | 176[.]124[.]199[.]207 | Stealc C&C server listed as a network indicator. |
| IPV4 | 188[.]114[.]96[.]1 | Amadey C&C server listed as a network indicator. |
| IPV4 | 193[.]156[.]1[.]16 | Amadey C&C server listed as a network indicator. |
| IPV4 | 194[.]26[.]192[.]191 | Stealc C&C server listed as a network indicator. |
| IPV4 | 196[.]251[.]107[.]130 | Stealc C&C server listed as a network indicator. |
| IPV4 | 62[.]60[.]226[.]159 | Amadey C&C server listed as a network indicator. |
| IPV4 | 64[.]188[.]91[.]237 | Stealc C&C server listed as a network indicator. |
| IPV4 | 94[.]154[.]35[.]25 | Amadey C&C server listed as a network indicator. |
| IPV4 | 95[.]85[.]238[.]4 | Stealc C&C server listed as a network indicator. |
| SHA1 | 09002d4668a778853e8da5c488c6e421c0628357 | SHA-1 hash of an Amadey sample. |
| SHA1 | 11a42ef076686cb27ba2c8845301943652a5aadc | SHA-1 hash of a sample identified as the Stealc infostealer. |
| SHA1 | 32d0c3300825b0bb991c4a8f1e6244f0ad2da989 | SHA-1 hash of a sample identified as the Stealc infostealer. |
| SHA1 | 38d744543b2051e6f749af171b5ef8d6df8aac7b | SHA-1 hash of an Amadey sample. |
| SHA1 | 5f3f99b14243404c7cf57b40bb101244cce394bf | SHA-1 hash of a sample identified as the Stealc infostealer. |
| SHA1 | 87867ad29e621bf9ebf57e1757f75090842458be | SHA-1 hash of an Amadey sample. |
| SHA1 | b4101027bf2f1261402bf6318c6eb016ce249037 | SHA-1 hash of a sample identified as the Stealc infostealer. |
| SHA1 | f61e3a643f2417e1a1ab2c83bbdbfc8a7cb96756 | SHA-1 hash of a sample identified as the Stealc infostealer. |
| SHA1 | ff8d2afd9d7f0a822092fee34ca55d1a3542f7ed | SHA-1 hash of an Amadey sample. |
MITRE ATT&CK
T1005 · Data from Local SystemStealc's configurable file grabber collects local files matching affiliate-defined patterns.T1008 · Fallback ChannelsAmadey samples can contain up to three C&C servers for use if the primary server becomes inaccessible.T1012 · Query RegistryAmadey reads registry data related to harvesting, Windows version, and keyboard layout.T1016 · System Network Configuration DiscoveryAmadey and Stealc send information about a compromised system's network setup to their C&C servers.T1020 · Automated ExfiltrationAmadey and Stealc can automatically exfiltrate collected data to their C&C servers.T1027 · Obfuscated Files or InformationStealc stores C&C addresses, URLs, and configuration strings encrypted with RC4 in its binary.T1027.015 · CompressionAmadey can download, decompress, and execute payloads delivered in ZIP archives.T1033 · System Owner/User DiscoveryAmadey and Stealc send the victim's username to their C&C servers.T1036 · MasqueradingStealc can masquerade as a legitimate binary.T1041 · Exfiltration Over C2 ChannelAmadey and Stealc exfiltrate collected data to their C&C servers.T1055.002 · Portable Executable InjectionAmadey can inject a downloaded payload into its child process.T1057 · Process DiscoveryAmadey's credential-stealer plugin and Stealc enumerate running processes.T1059.003 · Windows Command ShellAmadey can use cmd.exe to execute CMD script files.T1071.001 · Web ProtocolsAmadey communicates with C&C over HTTP; Stealc uses an HTTP(S), JSON-based protocol.T1082 · System Information DiscoveryAmadey and Stealc send system information, including Windows version and computer name, to their C&C servers.T1083 · File and Directory DiscoveryAmadey and Stealc search the file system for files, security products, and other artifacts of interest.T1106 · Native APIAmadey uses Windows API functions during execution.T1113 · Screen CaptureAmadey and Stealc can capture a screenshot when instructed.T1119 · Automated CollectionAmadey's plugin and Stealc's configured functionality automatically collect credentials and other data.T1129 · Shared ModulesAmadey can load credential-stealer and clipper plugins.T1132.001 · Standard EncodingAmadey uses hexadecimal and Base64 encodings for transferred data; Stealc uses Base64 for exfiltrated data in addition to RC4 encryption.T1136.001 · Local AccountAmadey can create an administrative account on a compromised system.T1140 · Deobfuscate/Decode Files or InformationAmadey and Stealc decrypt strings, network traffic, and downloaded payloads.T1195 · Supply Chain CompromiseAmadey and Stealc are distributed through trojanized or cracked software installers.T1204.002 · Malicious FileAmadey and Stealc are distributed as executable files that victims must run.T1218.007 · MsiexecAmadey can download and execute an additional payload distributed in an MSI package.T1218.011 · Rundll32Amadey can download and load an additional DLL using rundll32.exe.T1219.002 · Remote Desktop SoftwareAmadey supports remote control through its VNC plugin or an RDP connection.T1480 · Execution GuardrailsAmadey and Stealc check keyboard layout and abort execution when it matches a CIS country.T1518.001 · Security Software DiscoveryAmadey checks for installed security products and reports them to its C&C server.T1528 · Steal Application Access TokenStealc targets application access tokens, including tokens associated with cryptocurrency wallets and messaging apps.T1539 · Steal Web Session CookieStealc harvests browser cookies alongside credentials.T1547.001 · Registry Run Keys / Startup FolderAmadey can establish persistence for downloaded malware by creating a registry Run key.T1552.001 · Credentials In FilesAmadey and Stealc can harvest credentials from files, including application and wallet data.T1552.002 · Credentials in RegistryAmadey can harvest application credentials stored in the registry.T1555 · Credentials from Password StoresStealc targets browser-stored passwords and autofill data.T1555.003 · Credentials from Web BrowsersStealc and Amadey can harvest credentials stored by web browsers.T1573.001 · Symmetric CryptographyAmadey and Stealc use RC4 symmetric encryption for C&C communications.T1583.004 · ServerAmadey affiliates acquire servers to host C&C panels and support operations.T1587.001 · MalwareAmadey operators actively develop the malware and supporting capabilities.T1588.001 · MalwareAmadey affiliates acquire additional malware for distribution to compromised systems.T1608.001 · Upload MalwareAmadey and Stealc affiliates can upload acquired malware to their infrastructure or third-party web services for distribution.T1614.001 · System Language DiscoveryAmadey and Stealc check keyboard layout or locale to apply CIS-country execution blocks.
Threat Actors
Malware
Amadeyare once again collaborating with private partners and law enforcement, but this time taking aim at the Amadey botnet and Stealc infostealer, both provided via malware-as-a-service (MaaS) offerings.DanabotA year ago, ESET Research was part of two major operations that disrupted some of the leading cybercriminal operations at the time, Lumma Stealer and Danabot.Lumma StealerA year ago, ESET Research was part of two major operations that disrupted some of the leading cybercriminal operations at the time, Lumma Stealer and Danabot.StealCwith private partners and law enforcement, but this time taking aim at the Amadey botnet and Stealc infostealer, both provided via malware-as-a-service (MaaS) offerings.
Tools
Countries
EgyptOur telemetry detection rate, shown in Figure 2, indicates that Amadey was observed globally with no specific regional focus, although the highest detection rates were observed in India, Turkey, Egypt, Mexico, and Spain.IndiaOur telemetry detection rate, shown in Figure 2, indicates that Amadey was observed globally with no specific regional focus, although the highest detection rates were observed in India, Turkey, Egypt, Mexico, and Spain.ItalyThe highest detection rates were observed in the United States, Poland, and Italy.MexicoOur telemetry detection rate, shown in Figure 2, indicates that Amadey was observed globally with no specific regional focus, although the highest detection rates were observed in India, Turkey, Egypt, Mexico, and Spain.PolandThe highest detection rates were observed in the United States, Poland, and Italy.SpainOur telemetry detection rate, shown in Figure 2, indicates that Amadey was observed globally with no specific regional focus, although the highest detection rates were observed in India, Turkey, Egypt, Mexico, and Spain.TurkeyOur telemetry detection rate, shown in Figure 2, indicates that Amadey was observed globally with no specific regional focus, although the highest detection rates were observed in India, Turkey, Egypt, Mexico, and Spain.United StatesThe highest detection rates were observed in the United States, Poland, and Italy.