Last seven days
- First activity
- Sep 17, 2026
- Last activity
- Sep 17, 2026
- Feed role
- C2
- Host form
- 0 IP / 92 hostnames
Cutwail, also known as Pandex and closely associated with Pushdo, is a long-running Windows spam botnet and spambot malware family that emerged around 2007 and became one of the most prolific global sources of junk email.
Profile source: Mallory opens in a new tabCutwail
Cutwail, also known as Pandex and closely associated with Pushdo, is a long-running Windows spam botnet and spambot malware family that emerged around 2007 and became one of the most prolific global sources of junk email. It was commonly installed by the Pushdo downloader and operated through centralized command-and-control infrastructure that supplied message content and recipient lists, after which infected hosts sent spam directly over SMTP and reported delivery statistics and errors back to operators. Cutwail was widely used as a rentable criminal service by multiple spam groups and played a major role in the underground spam economy, including campaigns tied to online pharmacy spam and large-scale malware distribution.
Beyond bulk spam operations, Cutwail functioned as a malware delivery platform for other criminal ecosystems. It has been documented distributing or helping distribute malware including Gameover Zeus, CryptoLocker, Dridex, FakeRean, and other payloads delivered through broader downloader chains involving Pushdo and related infrastructure. It was also used in malspam campaigns targeting financial institutions and other organizations, including region-specific campaigns such as those delivering Ursnif in Japan. Some Cutwail variants and related operations used process-injection techniques, and the broader Pushdo/Cutwail ecosystem incorporated host profiling and security-product awareness to improve payload delivery and operational resilience.
Cutwail primarily targeted Microsoft Windows systems. At its height it was estimated to control hundreds of thousands to millions of infected hosts and to account for a substantial share of worldwide spam volume. Although best known for spam distribution, the botnet was also observed conducting distributed denial-of-service activity in at least one period, though that behavior appears secondary to its core role as a spam and malware distribution platform. Cutwail was the subject of multiple disruption and takedown efforts by researchers and law enforcement-adjacent defenders, reflecting its significance as one of the major spam botnets of its era.
C2 tracking
Derp observations, rolling seven-day window
Samples
74a19a12a8d5ec89f985cc23b0f93daa91fb1ac4cb1daafac2fafc68c1b4d852 759df96623d58120603e5fa42b7e7eeb98e72cf0ccffce5e6e033c87a685e973 987204ca82337f0a3f28097a5d66d5f3ecb11d43d82f67cd753d0bf2ce40b7a7 a6807d559eedefff6ff1d9d7e90e5765d1a0a1843139ec8eb03527b60e0630e4 d8f3d5f017e6385d2c47dc3ca86a789897f62ce18e13441e0f8c7e40a307b3d3 Reported operators
En 2019, le botnet Cutwail distribue Dridex ID 1044 via des campagnes dโhameรงonnage.
For many years, Cutwail has been among the top three most prolific spam botnets... versions of Cutwail are responsible for about 22 percent of the daily spam volumes worldwide. Security researchers have extensively dissected the technical machinery that powers Cutwail (a.k.a. โPushdoโ and โPandexโ)...
"...distribution via spam emails from GOLD ESSEX's Cutwail botnet..."
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.