Netskope Threat Labs

ANDROMEDA

ATP Sandbox Adv. HeuristicsAVNetskope IPS

ANDROMEDA (a.k.a. Gamarue) is a modular botnet that first appeared around 2011 and grew into one of the most widely distributed malware families of its era. It spreads through spam emails, exploit kits, and infected removable drives, and it acts as a downloader that pulls additional malware families onto infected systems. An international takedown in late 2017 disrupted much of its infrastructure, but code from the family continues to surface in new campaigns.

First seen
March 2022
Last seen
October 2026

7 techniques across 4 tactics.

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0008 Lateral Movement

  • T1091Replication Through Removable Media

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Backdoor.Andromeda
DeepScan:Generic.Andromeda.3FDB1080
DeepScan:Generic.Andromeda.46FEEDC6
DeepScan:Generic.Andromeda.59A7703E
DeepScan:Generic.Andromeda.8025F048
DeepScan:Generic.Andromeda.8F1695E9
DeepScan:Generic.Andromeda.A275C0BD
DeepScan:Generic.Andromeda.B4E833AA
DeepScan:Generic.Andromeda.BD3CA27F
DeepScan:Generic.Andromeda.BF8459E9