logo

LummaC Stealer Uses Amadey Bot To Deploy SectopRAT

ID: 0f7998a9-5e98-551c-b851-196c29af5b68

STIX ID: report--0f7998a9-5e98-551c-b851-196c29af5b68

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-24

Date Updated: 2026-07-17

...
...

This report details a multi-stage malware campaign in which the LummaC stealer (distributed via phishing and fake installers) harvests credentials and downloads the Amadey bot; Amadey persists via copied executables and LNK startup entries and then retrieves and executes SectopRAT, a Themida-packed .NET RAT that steals browser/crypto wallet data and provides remote access. The documentation includes sample hashes, C2 URLs and IPs, MITRE ATT&CK technique mappings, YARA and ET detection rules, and recommended defensive best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.