logo

Mapping Amadey Loader Infrastructure

ID: 2d04b3d2-755b-5732-adc0-d3001c22816d

STIX ID: report--2d04b3d2-755b-5732-adc0-d3001c22816d

Feed Name: IntelInsights (Substack)

Threat Score
71/100

Date Published: 2024-12-22

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

Researcher maps active Amadey Loader infrastructure by pivoting on urlscan resource hashes, uncovering consistent panel/URL naming, server configurations (Nginx 1.18.0 on Ubuntu and Apache 2.4.58), and concentrated hosting across several ASNs. A practical hunting rule is derived, leading to 16 unique IPs and 32 domains (listed), with observations on potential scanning countermeasures and limited infrastructure clustering via shared SSH fingerprints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.