logo

Amadey Equipped with AV Disabler drops Redline Stealer

ID: 37acc081-f62b-5c3d-8b28-577c25e6e3a7

STIX ID: report--37acc081-f62b-5c3d-8b28-577c25e6e3a7

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2023-07-28

Date Updated: 2026-04-27

...
...

**Executive Summary:** CloudSEK details an active multi-stage Amadey botnet campaign that uses chained droppers to install Healer.exe (a .NET Microsoft Defender disabler) and RedLine infostealer, resulting in permanent disabling of Microsoft Defender and Windows Update, establishment of persistence, and theft/interception of credentials and cryptocurrency; the report provides registry modifications, process/task persistence examples, IoCs (SHA256 hashes, IP addresses, URLs) and YARA rules for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.