
Amadey Stealer Runs 67-IP C2 Pool Engineered to Outlast Blocklists
A live Amadey stealer campaign is operating a command-and-control pool spanning more than twenty autonomous systems across a dozen countries. The infrastructure deliberately mixes automated TLS certificate rotation, compromised Korean residential broadband endpoints, and a Brazilian academic network address to fragment every possible takedown pathway.
Sixty-seven IP addresses. One stealer binary. And an infrastructure architecture so deliberately fragmented that no single takedown pathway touches more than a fraction of it. That is the operational picture CTX Team has assembled around a currently active Amadey stealer deployment — a campaign whose most distinctive feature is not the malware itself but the tiered, multi-continent command-and-control fabric the operators have constructed around it.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read