logo

Latest Amadey Uses Screen Capture, Pushes Remcos RAT

ID: 1aa5efd1-07b6-566c-a9d9-e53c83dda48f

STIX ID: report--1aa5efd1-07b6-566c-a9d9-e53c83dda48f

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ describes a new Amadey bot variant distributed via the RIG Exploit Kit: the sample unpacks in two stages, checks for AV, installs persistently, loads plugins (cred.dll to harvest stored credentials from apps like FileZilla/WinSCP and scr.dll to capture screenshots), and exfiltrates data to C2 servers (e.g., sh1091505.a.had.su). The analysis also shows Amadey actively pushing additional payloads (Remcos RAT) from its control panel, documents IOCs (hashes, domains, IPs), and notes broad infection telemetry (notably Windows 7 prevalence and geographic distribution).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.