Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Andromeda, also widely known as Gamarue and Wauchos, is a modular Windows bot malware family first observed in 2011 and active for years as a criminal malware-as-a-service and botnet platform.
Profile source: Mallory opens in a new tabANDROMEDA
Andromeda, also widely known as Gamarue and Wauchos, is a modular Windows bot malware family first observed in 2011 and active for years as a criminal malware-as-a-service and botnet platform. It is best known as an HTTP-based bot used to profile infected systems, maintain command-and-control communications, download and execute additional payloads, install plug-ins, update itself, and remove components on operator command. The family was heavily used as a distribution layer for other malware and appeared in multiple criminal ecosystems, including exploit-kit-driven infections and spam-delivered campaigns. It was also associated with broader botnet operations and later disruption efforts around 2017.
Andromeda commonly infected victims through exploit kits hosted on compromised websites, and it was also observed as an attachment or intermediate payload in email-borne malware campaigns. Some variants spread through infected USB media and worm-like abuse of Windows shortcut files, contributing to its broad reach. Once executed, Andromeda typically unpacked a small loader that used obfuscated API resolution, anti-debugging, anti-virtualization, and anti-analysis checks before injecting its payload into remote processes. Process hollowing and related in-memory execution were core traits, and later variants added stronger self-defense, watchdog behavior, persistence restoration, inline API hooking, and stealthier inter-process coordination.
Its command-and-control protocol used HTTP POST traffic with encrypted tasking and reporting. Across versions, Andromeda used RC4-based protection for outbound and inbound data, with later variants changing message formats and encryption details, including JSON-based structures in newer builds. Supported tasking included downloading and running executables, loading plug-ins, installing or deleting DLL-based components, self-updating, and uninstalling itself. The malware also gathered host metadata for bot identification and operational management.
Andromeda was frequently used as a first-stage delivery mechanism for other malware families, including banking trojans, credential stealers, spam bots, remote access tools, and DDoS bots. It has been linked in reporting to delivery chains involving UrlZone, Chthonic, Pony, Pushdo, Neutrino Bot, Proteus, and CoalaBot, among others. Criminal groups and affiliates, including actors tied to large spam and exploit-kit operations, used it as rentable infrastructure. Its prevalence, modularity, and role as a malware distribution platform made it one of the more significant commodity botnets of its era.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Début 2013, avant que le code malveillant Carbanak (alias Anunak, Sekur) ne soit développé, le groupe cybercriminel aurait souscrit à des Malware-as-a-Service, tels qu’Andromeda (alias Gamarue) et Pony.
...later campaigns occasionally used Pony or Andromeda as intermediate loaders to distribute various instances of Dridex.
"...use of the Andromeda Trojan as an initial payload in their attacks to download and execute other tools in their toolset."
"...a legacy ANDROMEDA sample was automatically installed and began to beacon out."
C0026 ... selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine through re-registered ANDROMEDA C2 domains.
...CodeFork leveraging the popular downloader Andromeda (aka Gamarue) to distribute a miner module to their existing botnets.
Exploited software
MITRE ATT&CK
Reporting
The Andromeda botnet, also tracked as Gamaru and Wauchos, operated for years as a modular Windows malware platform that steadily added stronger evasion, persistence, and command-and-control features. Analyses of versions including 2.7 through 2.10 show layered packing, anti-debugging and anti-VM checks, process injection and hollowing, watchdog-based self-repair, registry and autorun persistence, and encrypted HTTP communications using RC4, with later variants shifting to JSON-formatted C2 messages. The malware commonly spread through spam, phishing, compromised websites, illegal download portals, and exploit kits including Neutrino, Nuclear, Angler, and Rig, while using plug-ins for capabilities such as keylogging, form grabbing, rootkit functions, hidden TeamViewer access, and downloading additional malware.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.