One year ago, ESET Research played a key role in disrupting major cybercriminal operations such as Lumma Stealer and Danabot. Recently, our researchers have once again joined forces with private partners and law enforcement to target the Amadey botnet and Stealc infostealer, both offered as malware-as-a-service (MaaS) solutions. Operation Endgame, led by Microsoft Digital Crimes Unit (DCU) and other partners, aimed to dismantle the network infrastructure used by Amadey and Stealc affiliates to hinder their activities.
ESET contributed by providing technical analyses, statistical data, known command and control servers, encryption keys, campaign details, and other threat intelligence gathered during our extensive monitoring of these malware families.
Key points from this operation include:
ESET participated in Operation Endgame to disrupt the Amadey and Stealc malware families.
Around 50 domains and nearly 200 active IP-based C&C servers associated with Amadey and Stealc were impacted.
ESET shared technical analyses, statistical information, C&C servers, encryption keys, campaign identifiers, and other insights.
An overview of the MaaS ecosystem for both malware families was provided.
Clustering of Amadey and Stealc activities was described.
Technical aspects crucial for tracking and disruption, such as C&C communications, identifiers, and encryption keys, were summarized.
Overlap between Amadey and Lumma Stealer activities was detailed.
ESET Research has been tracking Amadey and Stealc for three years, sharing statistics and technical details for the disruption operation. Automated systems were utilized to dissect samples and identify key fields for tracking purposes. Clustering samples was a major focus to identify high-priority targets for disruption, given that both malware families are operated by affiliates running their own infrastructure.
Sharing technical analyses, statistics, and threat intelligence assists law enforcement in prioritizing and acting against malicious infrastructure. Around 50 domains and nearly 200 active IPs used as C&C servers for Amadey and Stealc were disrupted.
Amadey serves as a modular malware loader, distributing additional malware to compromised systems. Stealc functions as an infostealer targeting credentials, cookies, cryptocurrency wallets, and more. Both malware families are sold as services on the darknet, with affiliates managing their own infrastructure.
Distribution methods for Amadey and Stealc vary, with common delivery channels including fake software updates and cracked software installers. Amadey follows a pay-per-rebuild model, while Stealc offers unlimited build generation for affiliates. Both services caution against impersonation scams and provide official communication channels for prospective affiliates.
Amadey, advertised on darknet forums since October 2018, has a global presence with higher detection rates in countries like India, Turkey, Egypt, Mexico, and Spain. Its primary function is distributing malware to victims, along with modules for data exfiltration and remote access. Pricing for Amadey includes a $600 license fee and a $50 charge per rebuild. The pricing for Amadey has remained consistent since its early versions, indicating a loyal customer base. Significant updates were made to the codebase in August 2020 and October 2024, introducing new features aimed at evading antivirus detection.
Each Amadey sample includes a hardcoded C&C server URL and an RC4 key for encrypting communications. The RC4 key serves as a cluster identifier, grouping samples into botnets. Additionally, a random six-character hexadecimal string, known as sd, is used to identify specific builds within an affiliate’s deployment.
Amadey communicates with its C&C server over HTTP, following a three-stage lifecycle: initial beacon, registration, and tasking. Tasks are delivered as structured command strings, instructing the bot on various actions to perform.
Clustering Amadey samples is crucial for understanding the threat actor’s infrastructure. By analyzing C&C URLs, RC4 keys, and sd values, we identified 53 unique clusters within the Amadey ecosystem. The largest botnet cluster accounted for 34% of all processed samples and maintained consistent activity over time.
In conclusion, Amadey’s development has seen significant updates, with a focus on evading detection. Clustering samples helps identify key botnet clusters, providing insights into the threat actor’s operations. The largest botnet cluster remains active and prolific in distributing payloads to victims. Our clustering methodology revealed that the largest Amadey botnet distributed an average of around 14 payloads to each victim simultaneously. The malware families varied from infostealers to RATs, with complex code protectors. Multiple Lumma Stealer samples were also delivered to single victims, suggesting a pay-per-install model was in place.
In contrast, Stealc is an infostealer targeting various data sources globally. It is sold as a monthly subscription and has undergone multiple updates since its introduction. Each affiliate is responsible for its delivery mechanisms, with trojanized software installers and established malware loaders being common vectors.
Stealc communicates with its C&C server over HTTP using RC4-encrypted JSON objects. The C&C server responds with instructions for Stealc’s features, including exfiltrating data, fetching additional payloads, and signaling completion. The Stealc ecosystem is fractured into many small clusters, making disruption challenging.
Long-term automated tracking of malware is vital for global disruption operations against threats like Amadey and Stealc. Through our clustering methodology, we gained insights into the structure and operations of these botnets, aiding in our efforts to combat cyber threats. Hey there, fellow tech enthusiasts! Today, we’re diving deep into the world of MaaS (Malware-as-a-Service) with a focus on the Amadey and Stealc families. These families have a unique business model that involves often fragmented network infrastructure, specific identifiers, and communication protocols.
Our team at ESET has been hard at work dissecting the inner workings of these families, identifying key points for disruption. Through our threat intelligence and collaboration with partners, Operation Endgame was launched to disrupt the C&C servers used by Amadey and Stealc affiliates.
By seizing or rendering these servers inoperative, we directly impacted the infrastructure relied upon by these MaaS offerings’ affiliates. But our work doesn’t stop there. ESET will continue to monitor these families and track any attempts to rebuild operational infrastructure post-disruption.
For those interested in the nitty-gritty details, we’ve compiled a comprehensive list of indicators of compromise (IoCs) and samples in our GitHub repository. From file hashes to network IPs and domains, we’ve got you covered.
And let’s not forget about the MITRE ATT&CK techniques we’ve identified in our research. From initial access through execution, persistence, and exfiltration, we’ve mapped out how these families operate within the cyber threat landscape.
So, buckle up and join us on this journey as we unravel the complexities of Amadey and Stealc, and stay tuned for more updates on our ongoing efforts to combat cyber threats. Let’s keep the digital world safe and secure together! sentence in a different way:
The cat chased the mouse around the house.
The mouse was chased by the cat throughout the house.
