Description
ANDROMEDA (a.k.a. Gamarue) is a modular botnet that first appeared around 2011 and grew into one of the most widely distributed malware families of its era. It spreads through spam emails, exploit kits, and infected removable drives, and it acts as a downloader that pulls additional malware families onto infected systems. An international takedown in late 2017 disrupted much of its infrastructure, but code from the family continues to surface in new campaigns.
Stats
- First seen
- March 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
7 techniques across 4 tactics.
TA0005 Stealth
TA0008 Lateral Movement
- T1091Replication Through Removable Media
Associated campaigns
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Backdoor.Andromeda |
| DeepScan:Generic.Andromeda.3FDB1080 |
| DeepScan:Generic.Andromeda.46FEEDC6 |
| DeepScan:Generic.Andromeda.59A7703E |
| DeepScan:Generic.Andromeda.8025F048 |
| DeepScan:Generic.Andromeda.8F1695E9 |
| DeepScan:Generic.Andromeda.A275C0BD |
| DeepScan:Generic.Andromeda.B4E833AA |
| DeepScan:Generic.Andromeda.BD3CA27F |
| DeepScan:Generic.Andromeda.BF8459E9 |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC TROJAN.Andromeda Check-in Response Detected |