logo

Deconstructing Amadey’s Latest Multi-Stage Attack and Malware Distribution

ID: ef20e668-75a4-5b1b-a33d-8d4682a08e25

STIX ID: report--ef20e668-75a4-5b1b-a33d-8d4682a08e25

Feed Name: McAfee Labs Blog

Threat Score
78/100

Date Published: 2023-05-05

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs details a multi-stage malware campaign that leverages a malicious wextract.exe to unpack and execute successive payloads (cydn.exe → aydx.exe → mika.exe → vona.exe, etc.), disables Windows Defender via registry modifications, establishes persistence with scheduled tasks and ACL changes, and ultimately deploys Amadey components and RedLine Stealer to exfiltrate browser and wallet data; the report includes process flows, registry and ProcMon evidence, network C2 IPs, and SHA-256 IOCs for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.