MaaS operation using Emmenhtal and Amadey linked to threats against Ukrainian entities
ID: 080557ef-1d6d-519d-a968-cbf887cb9700
STIX ID: report--080557ef-1d6d-519d-a968-cbf887cb9700
Feed Name: Cisco Talos
Threat Score
Cisco Talos identified a Malware-as-a-Service operation (observed from Feb–Apr 2025) that used Emmenhtal multi-stage JavaScript/PowerShell loaders to deliver Amadey and other malware, staging payloads and plugins in public GitHub repositories to evade filtering; the activity overlaps with a SmokeLoader phishing campaign targeting Ukrainian organizations and includes detailed IOCs, TTP analysis (obfuscation layers, PowerShell/AES blobs, MP4 masquerades), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
