FILEMembers
FILE

Amadey Loader Hits Academic Networks Across 11 Countries via IE5 Cache

An unsigned 2 MB Win32 executable first seen on 2026-05-07 is delivering a credential-harvesting payload to education and research institutions across eleven countries. The sample stages through legacy Internet Explorer cache paths, embeds a secondary payload in its overlay section, and beacons over raw HTTP to a Seychelles-registered C2 node already on the Spamhaus DROP list.

May 28, 2026, 23:13 (UTC+9)Last seenMay 29, 2026Severity86ByCTX TeamActorAPT28StrontiumIOC4MITRE25RegionsBABOCOINMX

A freshly submitted Win32 executable — unsigned, just over 2 MB, first observed on VirusTotal on 2026-05-07 — is delivering a credential-harvesting payload to education and research institutions across eleven countries, using a staging chain that exploits legacy Internet Explorer cache paths, embeds a secondary payload in the binary's overlay section, and beacons home over raw HTTP to a single IPv4 address on a Seychelles-registered autonomous system that was provisioned less than nine months…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence