C&CMembers
C&C

Amadey Stealer Runs 67-IP C2 Pool Engineered to Outlast Blocklists

A live Amadey stealer campaign is operating a command-and-control pool spanning more than twenty autonomous systems across a dozen countries. The infrastructure deliberately mixes automated TLS certificate rotation, compromised Korean residential broadband endpoints, and a Brazilian academic network address to fragment every possible takedown pathway.

Jun 11, 2026, 15:27 (UTC+9)Last seenJun 11, 2026Severity100ByCTX TeamIOC70MITRE30

Sixty-seven IP addresses. One stealer binary. And an infrastructure architecture so deliberately fragmented that no single takedown pathway touches more than a fraction of it. That is the operational picture CTX Team has assembled around a currently active Amadey stealer deployment — a campaign whose most distinctive feature is not the malware itself but the tiered, multi-continent command-and-control fabric the operators have constructed around it.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence