Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military — Threadlinqs Intelligence
As of 2026-07-01, Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military is a high-severity malware threat attributed to Turla - G0010 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1029 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Turla - G0010 · Russia · ESPIONAGE
Amadey, a commodity Malware-as-a-Service loader first observed in October 2018, has evolved into a full-featured RAT with reverse TCP proxying, a TinyNuke-derived hidden VNC module,
Amadey emerged in October 2018 as a commodity Windows malware loader and information stealer sold as Malware-as-a-Service (MaaS) on Russian-language underground forums. Originally a straightforward payload distributor, Amadey has since evolved into a modular, full-featured Remote Access Trojan (RAT) that combines loader, stealer, network-pivoting, and interactive remote-control functionality in a single bot.
The modern bot targets 32-bit Windows primarily, with native 64-bit builds now observed, and is frequently deployed alongside SmokeLoader as an initial infection vector. Core loader functionality allows execution of arbitrary EXE, DLL, CMD, PowerShell, MSI, and ZIP payloads fetched from operator-controlled infrastructure. RAT-grade capabilities layered on top include a native reverse TCP proxy for pivoting into internal networks behind firewalls, a hidden VNC module derived from the leaked TinyNuke source code for stealthy interactive desktop access, creation of backdoor administrative accounts, and RDP enablement via registry modification plus firewall/service reconfiguration.
Information-theft plugins include a credential stealer (cred64.dll) that harvests browser, email, and FTP/SSH credentials, targets cryptocurrency wallets and Telegram session data, and sweeps the Desktop for documents; and a clipboard-clipping module (clip64.dll) that swaps cryptocurrency wallet addresses (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero) copied to the clipboard with attacker-controlled addresses via the Windows GetClipboardData API.
C2 communication is HTTP POST to up to three hardcoded C2 servers over .php endpoints, following a three-stage lifecycle: an initial 'st=s' beacon that queries the sleep interval, an RC4-encrypted registration POST containing a 12 key-value-pair system profile keyed to a unit ID derived from the first 12 numeric characters (offset 5) of the Windows SID, and a tasking response returning numbered command IDs wrapped in <c>/<d> tags and separated by '#'. Notable command IDs include 15/16 (reverse TCP proxy control), 18/19 (self-update/self-remove), 21 (credential stealer launch), 22 (clipboard clipper launch), 23 (hidden VNC activation), and 25 (backdoor admin account creation). Persistence is achieved via HKLM Run registry keys (enabled with a '!' prefix in payload URLs), administrative account creation, RDP auto-start service configuration, and a RunOnce failsafe that wipes the working directory on removal.
Amadey is the dominant loader observed delivering LockBit 3.0 ransomware payloads: malicious Word documents and Word-icon-spoofed executables drop Amadey, which in turn executes 'cc.ps1'/'dd.ps1' PowerShell LockBit droppers or the 'LBB.exe' LockBit binary, abusing the RemoteSigned PowerShell execution policy and using cacls.exe to set read-only permissions that resist deletion.
Separately, between March and April 2024 the Russian FSB (Center 16)-linked espionage actor Secret Blizzard (aka Turla, Waterbug, Venomous Bear, Snake) was observed by Microsoft using the Amadey bot — associated with financially-motivated actor Storm-1919 — either as MaaS or via surreptitious access to Amadey C2 panels, to selectively deploy PowerShell droppers against Ukrainian military devices egressing from Starlink IP ranges (a signature of front-line military connectivity). The intrusion chain progressed from the Amadey/Storm-1837 PowerShell backdoor, to a custom reconnaissance tool ('ddra.exe', RC4-encrypted runtime cmdlets for directory, session, routing-table, and SMB-share enumeration), to the Tavdig backdoor ('rastls.dll') loaded via DLL side-loading into the legitimate Symantec binary kavp.exe, and finally to installation of the persistent KazuarV2 backdoor, which injects into browser processes (explorer.exe, opera.exe) and communicates through compromised WordPress sites acting as C2 relays. Using existing cybercriminal loaders as cover let Secret Blizzard obscure state-sponsored espionage behind commodity-malware
Weaknesses (CWE)
CWE-506, CWE-494, CWE-1188
Target sectors: government administration, defense, military, finance, critical-infrastructure, all-industries
Target regions: ukraine, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566, T1059, T1106, T1547, T1136, T1112, T1053, T1140, T1027