Researchers from Trend Micro observed the APT group using another campaign on June 14, in which same FlawedAmmyy RAT distributed to target users in UAE but this time attackers using spam emails were delivered via the Amadey botnet. On June 20, through which threat actors are delivering undocumented malware named FlowerPippi. Researchers observed with the spam email campaigns delivering malware-embedded via.html or.xls file as an attachment and the Email body with social engineering technique to trick users into performing further infection.”]
Source: https://gbhackers.com/ta505-apt-hackers-new-malware-tools/