FlawedAmmyy

References:
  • Leaked Ammyy Admin Source Code Turned into Malware - 2018-03-07 - Proofpoint - Proofpoint Staff FlawedAmmyy TA505 Quant
  • An in-depth malware analysis of QuantLoader - 2018-03-28 - Malwarebytes - Vishal Thakur Quant TA505 FlawedAmmyy
  • More Reading:

  • TA505 Abusing SettingContent-ms within PDF files to Distribute FlawedAmmyy RAT - 2018-07-19 - Proofpoint - Proofpoint Staff FlawedAmmyy TA505
  • URLZone top malware in Japan, while Emotet and LINE Phishing round out the landscape - 2019-06-19 - Proofpoint - Proofpoint Staff TA544 URLZone Gozi v3 Vawtrak TA505 FlawedAmmyy
  • Anomaly detection helped us uncover a new campaign that employs a complex infection chain to download and run the notorious FlawedAmmyy RAT directly in memory. - 2019-06-21 - Twitter - Microsoft Security Intelligence FlawedAmmyy TA505
  • TA505 begins summer campaigns with a new pet malware downloader, AndroMut, in the UAE, South Korea, Singapore, and the United States - 2019-07-02 - Proofpoint - Matthew Mesa - Dennis Schwarz - Proofpoint Staff AndroMut FlawedAmmyy TA505
  • Sandiflux Botnet Report - June 2019 - 2019-07-02 - Slideshare - Salvatore Saeli TA505 FlawedAmmyy GandCrab Sodinokibi
  • (PDF) Silence 2.0: Going Global - 2019-07-04 - Group-IB Silence FlawedAmmyy
  • PDF: ASEC REPORT vol.96 Q3 2019 - 2019-10-11 - Ahnlab - ASEC Researchers Clop SDBbot FlawedAmmyy TA505
  • TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader - 2019-10-16 - Proofpoint - Dennis Schwarz - Kafeine - Matthew Mesa - Axel F - Proofpoint Staff Get2 TA505 SDBbot FlawedGrace FlawedAmmyy Snatch ServHelper