Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 00:59:42 UTC Home > List all groups > List all tools > List all groups using tool Amavaldo Tool: Amavaldo Names Amavaldo Category Malware Type Banking trojan, Backdoor, Keylogger, Info stealer, Credential stealer Description (ESET) Most Latin American banking trojans we have analyzed connect to the C&C server and stay connected, waiting for whatever commands the server sends. After receiving a command, they execute it and wait for the next one. The commands are probably pushed manually by the attacker. You can think of this approach as a chat room where all the members react to what the admin writes. Information Last change to this tool card: 21 April 2021 Download this tool card in JSON format All groups using tool Amavaldo Changed Name Country Observed Unknown groups _[ Interesting malware not linked to an actor yet ]_ 1 group listed (0 APT, 0 other, 1 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f04824f9-64ff-4ac5-94cc-cd3d067abbb1 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f04824f9-64ff-4ac5-94cc-cd3d067abbb1 Page 1 of 1