FlawedAmmyy

Malware

⚠️ Overview

FlawedAmmyy is a remote access trojan (RAT) first observed in mid-2018 by Proofpoint, derived from the legitimate commercial remote desktop tool Ammyy Admin. It is attributed to the financially motivated threat group TA505 (also tracked as FIN11) and functions as a modular backdoor for initial access, often preceding deployment of secondary payloads like FlawedGrace or ransomware (e.g., Clop). MITRE ATT&CK categorizes it under software ID S0394.

🔧 Technical Capabilities

FlawedAmmyy propagates via spearphishing emails with malicious Microsoft Office documents (often leveraging macro-based droppers). Its attack vectors include weaponized Excel attachments and fake invoice lures. The RAT communicates with its command-and-control (C2) infrastructure over HTTP, using RC4 encryption with a hardcoded 256-bit key to hide traffic. Persistence is achieved by adding a registry Run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun“AmmyyAdmin”) or creating a scheduled task. Evasion techniques include process injection into legitimate processes (e.g., explorer.exe or svchost.exe) and obfuscating payloads with custom packers. It also uses a dynamic API resolution to bypass static detection. C2 servers often employ domain generation algorithms (DGAs) and fast-flux DNS to resist takedowns.

📜 History & Notable Incidents

First documented in November 2018 by Proofpoint, FlawedAmmyy was deployed in TA505 campaigns targeting financial services, healthcare, and retail sectors. A notable incident in early 2020 involved a large-scale phishing wave delivering FlawedAmmyy to European banks, later linked to the deployment of Clop ransomware. No specific CVEs are exploited by the malware itself, but it leverages macro execution vulnerabilities (e.g., CVE-2017-0199 for older Office versions) in attendant droppers. Law enforcement actions include the 2021 arrest of several TA505 affiliates by Ukrainian police, though the group remains active.

🔍 Detection Indicators

File hashes for FlawedAmmyy samples include MD5: 0x9F8E7A3C5B2D1E4F6A8B0C9D1E2F3A4B (example) and SHA256 hashes reported by VirusTotal. Behavioral signatures include creation of the mutex named “AmmyyAdminMutex” and registry keys under HKCUSoftwareAmmyyAdmin. Network IOCs consist of HTTP POST requests to URLs containing “/gate” or “/c2” with a User-Agent string of “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.143 Safari/537.36” (observed in TA505 campaigns). C2 IP addresses frequently resolve from dynamic DNS domains like “update.duckdns.org”.

☠️ Risk & Impact

FlawedAmmyy enables full remote control of infected systems, allowing threat actors to exfiltrate sensitive data (e.g., credentials, financial records) and deploy ransomware—causing average incident costs exceeding $1 million per breach. The majority of victims are in the financial and healthcare industries, with public sector entities also targeted. Data exfiltration is achieved through compressed HTTP uploads, and the RAT’s keylogging capability captures financial transactions in real time.

🛡️ Mitigation

Defenders should block execution of the legitimate Ammyy Admin binary (if unused) via application whitelisting, enable macro security controls in Office, and deploy endpoint detection rules for the specific mutex, registry keys, and HTTP User-Agent strings listed above. SIEM rules matching traffic to known FlawedAmmyy C2 domains and YARA signatures for RC4-encrypted payloads are also recommended. Regularly patch Office vulnerabilities (e.g., CVE-2017-0199) and use multi-factor authentication to reduce lateral movement risk.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.