Deconstructing Amadey’s Latest Multi-Stage Attack and Malware Distribution
ID: ef20e668-75a4-5b1b-a33d-8d4682a08e25
STIX ID: report--ef20e668-75a4-5b1b-a33d-8d4682a08e25
Feed Name: McAfee Labs Blog
McAfee Labs details a multi-stage malware campaign that leverages a malicious wextract.exe to unpack and execute successive payloads (cydn.exe → aydx.exe → mika.exe → vona.exe, etc.), disables Windows Defender via registry modifications, establishes persistence with scheduled tasks and ACL changes, and ultimately deploys Amadey components and RedLine Stealer to exfiltrate browser and wallet data; the report includes process flows, registry and ProcMon evidence, network C2 IPs, and SHA-256 IOCs for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
