Skip to content

ANDROMEDA

Andromeda, also widely known as Gamarue and Wauchos, is a modular Windows bot malware family first observed in 2011 and active for years as a criminal malware-as-a-service and botnet platform.

Profile source: Mallory opens in a new tab

ANDROMEDA

Family profile

Andromeda, also widely known as Gamarue and Wauchos, is a modular Windows bot malware family first observed in 2011 and active for years as a criminal malware-as-a-service and botnet platform. It is best known as an HTTP-based bot used to profile infected systems, maintain command-and-control communications, download and execute additional payloads, install plug-ins, update itself, and remove components on operator command. The family was heavily used as a distribution layer for other malware and appeared in multiple criminal ecosystems, including exploit-kit-driven infections and spam-delivered campaigns. It was also associated with broader botnet operations and later disruption efforts around 2017.

Andromeda commonly infected victims through exploit kits hosted on compromised websites, and it was also observed as an attachment or intermediate payload in email-borne malware campaigns. Some variants spread through infected USB media and worm-like abuse of Windows shortcut files, contributing to its broad reach. Once executed, Andromeda typically unpacked a small loader that used obfuscated API resolution, anti-debugging, anti-virtualization, and anti-analysis checks before injecting its payload into remote processes. Process hollowing and related in-memory execution were core traits, and later variants added stronger self-defense, watchdog behavior, persistence restoration, inline API hooking, and stealthier inter-process coordination.

Its command-and-control protocol used HTTP POST traffic with encrypted tasking and reporting. Across versions, Andromeda used RC4-based protection for outbound and inbound data, with later variants changing message formats and encryption details, including JSON-based structures in newer builds. Supported tasking included downloading and running executables, loading plug-ins, installing or deleting DLL-based components, self-updating, and uninstalling itself. The malware also gathered host metadata for bot identification and operational management.

Andromeda was frequently used as a first-stage delivery mechanism for other malware families, including banking trojans, credential stealers, spam bots, remote access tools, and DDoS bots. It has been linked in reporting to delivery chains involving UrlZone, Chthonic, Pony, Pushdo, Neutrino Bot, Proteus, and CoalaBot, among others. Criminal groups and affiliates, including actors tied to large spam and exploit-kit operations, used it as rentable infrastructure. Its prevalence, modularity, and role as a malware distribution platform made it one of the more significant commodity botnets of its era.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Aug 29, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • IE1

Leading providers

  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
Carbanak

Début 2013, avant que le code malveillant Carbanak (alias Anunak, Sekur) ne soit développé, le groupe cybercriminel aurait souscrit à des Malware-as-a-Service, tels qu’Andromeda (alias Gamarue) et Pony.

TA505

...later campaigns occasionally used Pony or Andromeda as intermediate loaders to distribute various instances of Dridex.

Transparent Tribe

"...use of the Andromeda Trojan as an initial payload in their attacks to download and execute other tools in their toolset."

UNC4210

"...a legacy ANDROMEDA sample was automatically installed and began to beacon out."

Turla

C0026 ... selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine through re-registered ANDROMEDA C2 domains.

CodeFork

...CodeFork leveraging the popular downloader Andromeda (aka Gamarue) to distribute a miner module to their existing botnets.

Exploited software

Vulnerabilities linked to ANDROMEDA

3 CVEs

MITRE ATT&CK

ANDROMEDA in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1091 Replication Through Removable Media T1055 Process Injection T1566 Phishing T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1059.003 Windows Command Shell T1071.001 Web Protocols T1547.001 Registry Run Keys / Startup Folder T1027.013 Encrypted/Encoded File T1547.009 Shortcut Modification T1082 System Information Discovery T1497 Virtualization/Sandbox Evasion T1027 Obfuscated Files or Information T1055.012 Process Hollowing T1574.001 DLL T1059 Command and Scripting Interpreter T1622 Debugger Evasion T1112 Modify Registry T1012 Query Registry T1189 Drive-by Compromise T1566.001 Spearphishing Attachment T1583 Acquire Infrastructure T1036 Masquerading T1203 Exploitation for Client Execution T1543 Create or Modify System Process T1070.004 File Deletion T1559.001 Component Object Model T1071.004 DNS T1497.001 System Checks T1559 Inter-Process Communication T1573 Encrypted Channel T1055.004 Asynchronous Procedure Call T1564.001 Hidden Files and Directories T1056.003 Web Portal Capture T1106 Native API T1059.005 Visual Basic T1219 Remote Access Tools T1070.006 Timestomp T1001 Data Obfuscation T1070 Indicator Removal T1204.002 Malicious File T1614.001 System Language Discovery T1190 Exploit Public-Facing Application T1033 System Owner/User Discovery T1046 Network Service Discovery T1005 Data from Local System T1218.011 Rundll32 T1036.005 Match Legitimate Resource Name or Location T1584.005 Botnet T1210 Exploitation of Remote Services T1583.001 Domains T1036.006 Space after Filename T1036.008 Masquerade File Type T1092 Communication Through Removable Media T1568.003 DNS Calculation T1584 Compromise Infrastructure T1204 User Execution

Reporting

Research mentioning ANDROMEDA

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.