The same malware is also being spread by #Amadey pay-per-install (PPI):
➡️ urlhaus.abuse.ch/url/3733103/
We’ve identified an interesting malware family 🔍, which we’ve named #GrokPy due to its use of a Grok LLM model 🤖 to solve and subsequently bypass CAPTCHAs 🔥
The malware gets dropped by #Amadey and:
Potential new stealer dropped by #Amadey 🤖🔍Who can name it? ⤵️
👉 hunting.abuse.ch/hunt/6919ec1...
Botnet C2 domains:
📡defender-temeerty .sbs
📡telemetry-defender .lol
Botnet C2 server:
🛑185.100.157.69:443 (Partner Hosting 🇬🇧)
Malware sample:
📄 bazaar.abuse.ch/sample/903cd...
Lumma Stealer Slowed by Doxxing Campaign The prolific threat actors behind the Lumma Stealer malware have been slowed by an underground doxxing campaign in recent months. Coordinated law enforcemen...
#Cyber #News #Firewall #Daily #Amadey #Bot […]
[Original post on thecyberexpress.com]
We encountered a a new loader advertised as "Morpheus" in underground forums 🕵️, recently dropped by #Amadey ⬇️🪲. Morpheus' C2 protocol is based on HTTP and working with tasks, where each task consists of an ID and a command 📣
Botnet C2: sophos-upd-srv .info 🇳🇱
Campagna MaaS usa Emmenhtal e Amadey per colpire entità ucraine via GitHub. Talos rivela tattiche e IOC per la mitigazione.
#Amadey #CiscoTalos #Emmenhtal #github #MaaS #SmokeLoader #ucraina
www.matricedigitale.it/2025/07/17/o...
StealC Malware Gets a Major Upgrade, Becomes More Dangerous #2FA #Amadey #InfoStealer
Just discovered a staged dropper chain (Amadey + RedLine Stealer)
hiding inside iolo’s AV SDK folder.
Defender: "threat not fully removed".
Confirmed by Dr.Web LiveDisk. SSD removed.
Full writeup + screenshots coming.
Anyone else seen AVs protecting the malware itself?
#infosec #malware #amadey
Another day, another #Amadey 📅👀 This time dropping #SystemBC ⤵️
Amadey botnet C2:
📡cobolrationumelawrtewarms .com
📡107.189.27.66 (AS14956 ROUTERHOSTING 🇳🇱)
SystemBC payload:
📄bazaar.abuse.ch/sample/c13d59dc2e8ee1cbd...
We have observed #Amadey (ID: 092155) dropping #BumbleBee on an infected device, leveraging a new DGA seed 🔥
DGA domains:
🌐https://threatfox.abuse.ch/browse/tag/e5774fe6340da26c/
Malware sample:
📄bazaar.abuse.ch/sample/f39ac7d6c65d67bca...
🌍 #𝗖𝗬𝗕𝗘𝗥𝗩𝗘𝗜𝗟𝗟𝗘 🌍
Le malware #Amadey vous force à entrer vos identifiants Google : voici comment échapper à ce vol d'informations
buff.ly/47vPpnH