Latest Amadey Uses Screen Capture, Pushes Remcos RAT
ID: 1aa5efd1-07b6-566c-a9d9-e53c83dda48f
STIX ID: report--1aa5efd1-07b6-566c-a9d9-e53c83dda48f
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ describes a new Amadey bot variant distributed via the RIG Exploit Kit: the sample unpacks in two stages, checks for AV, installs persistently, loads plugins (cred.dll to harvest stored credentials from apps like FileZilla/WinSCP and scr.dll to capture screenshots), and exfiltrates data to C2 servers (e.g., sh1091505.a.had.su). The analysis also shows Amadey actively pushing additional payloads (Remcos RAT) from its control panel, documents IOCs (hashes, domains, IPs), and notes broad infection telemetry (notably Windows 7 prevalence and geographic distribution).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
