本サイトは、快適にご利用いただくためにクッキー(Cookie)を使用しております。
Cookieの使用に同意いただける場合は「同意する」ボタンを押してください。
なお本サイトのCookie使用については、「個人情報保護方針」をご覧ください。
Mitsui Bussan Secure Directions (MBSD) Joins Microsoft-Led Take Down of the “Amadey” and “StealC” Malware as the Only Participating Company from Japan
— Contributing to the Disruption of an Attack Infrastructure That Serves as a Launchpad for Infostealers and Ransomware —
The Cyber Intelligence Group (CIG) of Mitsui Bussan Secure Directions, Inc. (MBSD / Head Office: Chuo-ku, Tokyo; President and CEO: Daisen Suzuki) has become the only Japanese company to participate in an international joint project led by Microsoft to take down (disruption) the infrastructure behind the “Amadey” and “StealC” malware.
“Amadey” is a loader-type (bot-type) malware that collects information from infected devices while pulling in additional malware, while “StealC” is an information-stealing malware (infostealer) that exfiltrates credentials and other data. Both have long been exploited worldwide as a starting point for data breaches and ransomware attacks.
Beyond being used as standalone attack tools, these malware families are also distributed as part of Malware-as-a-Service offerings that provide functionality and access to criminals, creating the risk of being exploited in a wide range of cybercrimes.
This action was taken pursuant to a lawsuit that Microsoft filed in the U.S. District Court for the Southern District of Florida, and was carried out against globally deployed Malware-as-a-Service cybercrime infrastructure. The infrastructure in question is reported to have been abused for purposes including financial fraud, account compromise, unauthorized use of applications and services, and theft of confidential information.
The operation was carried out in cooperation with Microsoft, as well as law enforcement agencies including Europol EC3, Germany’s Federal Criminal Police Office, the Danish National Police, and the Dutch National Police, and private cybersecurity companies including ESET, BitSight, Lumen, IBM, and Proofpoint. MBSD participated in this effort as the only Japanese cybersecurity company. The response to StealC was conducted as part of Operation Endgame.
■ MBSD’s Role
MBSD’s CIG has continuously monitored Amadey’s C2 servers over a long period of approximately six and a half years. For this project, by drawing on the data and expertise we hold and by cooperating with Microsoft and other relevant agencies and companies, we helped bring the project to fruition. For a technical analysis of CIG’s long-term monitoring of Amadey’s C2 servers, please refer to this blog post.
■ The Significance of Taking Down Cybercrime Infrastructure
This action does more than prevent individual malware infections; it is a countermeasure aimed at the very infrastructure that cybercriminals depend on.
Because Malware-as-a-Service criminal infrastructure makes malware usable even by attackers with limited technical skill, it is a factor that accelerates the spread of cybercrime. Shutting down such infrastructure helps prevent harm before it occurs, raises the operational costs for criminals, and deters future attacks.
Through international public-private initiatives such as this one, MBSD will continue to contribute to deter cybercrime that targets organizations and individuals both in Japan and overseas.
■ Comment from MBSD
Takashi Yoshikawa, Fellow at Mitsui Bussan Secure Directions, Inc. and the leader of CIG, said:
“Malware like Amadey and StealC is not merely a standalone threat; It has become an essential component that underpins the growing specialization and the rise of ready-made services in cybercrime. Countering the criminal infrastructure itself through international efforts like this one is critically important to prevent the damage from spreading. Going forward, MBSD will continue to contribute to strengthening cybersecurity across society through the investigation and analysis of threat intelligence.”
About Mitsui Bussan Secure Directions (MBSD)
Founded in 2001 as a company specializing in cybersecurity. MBSD provides advanced security technology services and consulting services, including penetration testing / TLPT / red team exercises; a range of assessment services such as web application and network vulnerability assessments; malware analysis; and integrated log monitoring / Managed XDR services. The company is home to a large number of Japan’s most highly skilled security professionals.
About the Cyber Intelligence Group (CIG)
CIG is the specialized team within Mitsui Bussan Secure Directions (MBSD) responsible for malware analysis, investigating the real-world activities of ransomware groups, and the collection and analysis of threat intelligence. In addition to publishing information based on its own original research, it is also actively engaged in explaining threat trends through the media.
<Inquiries Regarding This Matter>
Mitsui Bussan Secure Directions, Inc.
Cyber Intelligence Group (CIG)
https://www.mbsd.jp/contact-list/