Hacker’s jargon: build (not to be confused with build in co)
The Anatomy of a Build: Inside the Underground Economy of Amadey and Its Criminal Ecosystem. “Build” as the Currency of the Underground
Hacker’s jargon: build (not to be confused with build in coding)
The Anatomy of a Build: Inside the Underground Economy of Amadey and Its Criminal Ecosystem. “Build” as the Currency of the Underground
In the world of legitimate software development, the word build carries a straightforward meaning: the compiled result of source code, packaged and ready for deployment or distribution. In underground slang, however, a build is far more than a mere binary. It is the unit of currency in a marketplace that thrives on secrecy, distrust, and predation. A build is a promise: of working code, of bypassed defenses, of a foothold inside a victim’s machine.

The screenshots we analyze here come from Amadey, a well-known malware family that began its life as a bespoke product. Initially written under strict technical specifications for a private client, Amadey was later released under license and spread widely on underground forums. It is a prime example of what a build looks like when polished for the black market: complete with panel, tasking system, stealer modules, and dashboards that wouldn’t look out of place in a SaaS product.
But behind the shine of Amadey’s build lies a world that is anything but orderly. Hackers are not solitary masterminds orchestrating attacks in isolation. Instead, they exist within a decentralized ecosystem: developers, cryptors, botnet operators, resellers, and brokers. Around them swarm opportunists, scammers, and impostors. Everyone feeds on everyone else. And while the underground is flooded with noise, only a handful of true specialists create the kind of builds that shape the global threat landscape.
Amadey illustrates this ecosystem in practice.
The Amadey Build: Features of a Commodity
The first screenshot reads like a product brochure — except the product is crimeware. Amadey boasts two independent loaders (C++ and PHP), full compatibility with Windows versions from 7 to Server 2025, support for autorun, DLL execution through rundll32, and persistent launch control that retries failed infections up to three times.
Other highlights:
- Autorun and persistence: the build can run after reboot or rely on Windows registry keys.
- Per-unit personalization: unique DES encryption constants for each build.
- Exclusion zones: not operational in the Russian Federation and allied countries, a familiar clause in Eastern European malware.
- FastFlux synchronization: ensuring resilient command-and-control.
- Stealer integration: 12 types of antivirus bypasses defined, with expansion promised.
Even the marketing language feels eerily corporate. Amadey promises “powerful statistics without unnecessary water,” a jab at bloated dashboards. It emphasizes ease of deployment: database setup and table creation are all handled from the control panel.

Perhaps the most striking feature is its detection rate. In October 2018, a non-crypted executable build was tested against antivirus solutions. Only 3 out of 23 detected it. And this was the raw, unencrypted version compiled directly from source. Once crypted — obfuscated and packed to evade detection — its footprint would be even smaller.
For an underground buyer, this makes Amadey a highly attractive build. The screenshots double as a live demo: proof that the binary runs cleanly against most antivirus engines, that it knocks back to command-and-control (C2) servers, and that it can deliver stolen data at scale.

From Tasking to Credentials: The Life of an Amadey Infection
Subsequent screenshots open the curtain on Amadey’s operational side. The control panel interface is sleek, offering task management, statistics, and per-unit tracking. In one panel, the operator has a single active task: delivering a CMD script (1.cmd) to infected machines, saving it to %Desktop%. Out of 100 targeted units, 13 received the task, one executed successfully, and others failed to launch or report.
The “Units list online” resembles an admin console for a SaaS app. Each entry shows:
- Unique ID of the infected unit
- Country flag and IP address
- Operating system version
- Owner type (User, Admin)
- Last seen online
In the sample list, units report in from India, Indonesia, the United States, Australia, Macedonia, the Philippines, Martinique, and Pakistan. Some machines belong to regular users, others to administrators. The system notes whether the stub was crypted and the Amadey version (5.21 in this case).

The stealer’s output is even more telling. Rows of stolen credentials flow in, harvested from browsers (Firefox, Chrome, Edge, Opera), FTP clients (FileZilla, WinSCP), email (Outlook), and messaging software (Pidgin, Comodo). Credentials include logins to Google, LinkedIn, Facebook, Reddit, and financial portals. This is the real treasure: kredy in underground slang. They are the payoff that fuels resale markets for corporate access, personal accounts, and further exploitation.
The process is automated. Amadey handles the dirty work of keylogging and credential extraction; the operator views the results in a clean table. Each line item can be exported, resold, or fed into another campaign.
The Jargon of the Underground: Decoding the Build Economy
To outsiders, this may look like a technical dashboard. To insiders, it is the stage for an entire lexicon:
- Build: the compiled binary tailored for the buyer. Each build is unique, tied to DES keys and licensing.
- Crypt: the process of obfuscating a build to bypass detection. Selling a “non-crypt” build is proof of honesty; the buyer must still crypt it before deployment.
- Stuk (Knock): the callback signal from an infected machine, confirming it is alive and reporting to C2.
- Zalivka (Flood/Upload): mass deployment of the build, either via phishing, exploit kits, or spam runs.
- Kredy (Credentials): the stolen logins and passwords that form the real value of a stealer build.
This jargon is not decorative — it reflects a transactional reality. A buyer wants guarantees: that a build will knock, that it will survive reboot, that it will deliver usable kredy. A seller wants to prove their build works. Thus, screenshots of dashboards, unit lists, and stealer tables become essential marketing collateral.
The Human Infrastructure Behind the Code
A common misconception is that malware like Amadey is the creation of a lone hacker genius. In truth, builds emerge from a decentralized, overlapping infrastructure.
- Coders design the core malware. Their skill is rare, and they often remain in the shadows.
- Cryptors specialize in evasion, selling services that wrap builds in layers of obfuscation.
- Botnet operators acquire builds and distribute them, managing infections and monetizing stolen data.
- Resellers and brokers advertise builds in forums, often without owning the code. Many are outright scammers.
- Buyers range from petty criminals running spam campaigns to organized groups targeting corporations.
It is an ecosystem built on distrust. Partnerships form and dissolve quickly. Rival groups sabotage each other, flood markets with fake builds, or launch denial-of-service attacks on competitors’ panels. The underground is not a cartel; it is a swarm.
And within this swarm, true specialists are scarce. For every developer capable of writing a loader as polished as Amadey’s, there are dozens of pretenders recycling code, repackaging stolen builds, or running scams. This imbalance is what makes builds so valuable: they are bottlenecks in a marketplace where demand outstrips talent.
A Predator’s Marketplace: Everyone Eats Everyone
The underground market for builds is not governed by rules of honor. It is a Darwinian environment. Fraudsters sell fake panels with hardcoded credentials, collecting money and disappearing. Competitors “leak” each other’s builds to devalue rivals. Some groups form alliances, only to fracture when disputes over profit arise.
Amadey’s evolution reflects this predatory cycle. Originally designed for one client, it escaped into circulation, where others copied, modified, and resold it. Soon, it became a commodity. Versions like 5.21, seen in the screenshots, spread globally. Operators in India, the U.S., and Southeast Asia used the build to harvest thousands of kredy.
- Credential theft at scale: accounts stolen from Google, Facebook, LinkedIn, and FTP servers provide direct access into personal and corporate systems.
- Low detection rates: even uncrypted, Amadey evades most antivirus products.
- Ease of use: a slick dashboard lowers the barrier of entry, enabling low-skill actors to run campaigns.
- Resilience: features like FastFlux and automatic retries make infections persistent.
The implications are global. When a single build can seed infections across continents, from India to Macedonia, defenders cannot dismiss it as just another stealer. It is a replicating threat, multiplied by the ecosystem that surrounds it.
The Build Economy as Dark SaaS
Amadey is more than a piece of malware. It is a case study in how cybercrime mirrors legitimate industries. Just as companies rely on SaaS products for scalability, criminals rely on builds for efficiency. Panels, dashboards, licensing, versioning — all the hallmarks of modern software — are present in the underground.
The screenshots remind us: cybercrime is not a world of lone wolves but of swarms. A decentralized infrastructure of coders, cryptors, operators, and brokers, bound together by distrust and greed. In this world, the build is the coin of the realm.
For defenders, recognizing this reality is essential. Fighting malware like Amadey means not only dissecting its binaries but understanding the predator’s marketplace that sustains it.
메타데이터
- post_id
- e70a4aa10a0c
- slug
- hackers-jargon-build-not-to-be-confused-with-build-in-co-e70a4aa10a0c
- url
- https://medium.com/@0trust0day/hackers-jargon-build-not-to-be-confused-with-build-in-co-e70a4aa10a0c
- canonical_url
- https://medium.com/@0trust0day/hackers-jargon-build-not-to-be-confused-with-build-in-co-e70a4aa10a0c
- author_url
- https://medium.com/@0trust0day
- status
- ok
- fetched_at
- 2026-07-18 05:02:09