Amadey Equipped with AV Disabler drops Redline Stealer
ID: 37acc081-f62b-5c3d-8b28-577c25e6e3a7
STIX ID: report--37acc081-f62b-5c3d-8b28-577c25e6e3a7
Feed Name: CloudSEK Blog
**Executive Summary:** CloudSEK details an active multi-stage Amadey botnet campaign that uses chained droppers to install Healer.exe (a .NET Microsoft Defender disabler) and RedLine infostealer, resulting in permanent disabling of Microsoft Defender and Windows Update, establishment of persistence, and theft/interception of credentials and cryptocurrency; the report provides registry modifications, process/task persistence examples, IoCs (SHA256 hashes, IP addresses, URLs) and YARA rules for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
