Skip to content

Cutwail

Cutwail, also known as Pandex and closely associated with Pushdo, is a long-running Windows spam botnet and spambot malware family that emerged around 2007 and became one of the most prolific global sources of junk email.

Profile source: Mallory opens in a new tab

Cutwail

Family profile

Cutwail, also known as Pandex and closely associated with Pushdo, is a long-running Windows spam botnet and spambot malware family that emerged around 2007 and became one of the most prolific global sources of junk email. It was commonly installed by the Pushdo downloader and operated through centralized command-and-control infrastructure that supplied message content and recipient lists, after which infected hosts sent spam directly over SMTP and reported delivery statistics and errors back to operators. Cutwail was widely used as a rentable criminal service by multiple spam groups and played a major role in the underground spam economy, including campaigns tied to online pharmacy spam and large-scale malware distribution.

Beyond bulk spam operations, Cutwail functioned as a malware delivery platform for other criminal ecosystems. It has been documented distributing or helping distribute malware including Gameover Zeus, CryptoLocker, Dridex, FakeRean, and other payloads delivered through broader downloader chains involving Pushdo and related infrastructure. It was also used in malspam campaigns targeting financial institutions and other organizations, including region-specific campaigns such as those delivering Ursnif in Japan. Some Cutwail variants and related operations used process-injection techniques, and the broader Pushdo/Cutwail ecosystem incorporated host profiling and security-product awareness to improve payload delivery and operational resilience.

Cutwail primarily targeted Microsoft Windows systems. At its height it was estimated to control hundreds of thousands to millions of infected hosts and to account for a substantial share of worldwide spam volume. Although best known for spam distribution, the botnet was also observed conducting distributed denial-of-service activity in at least one period, though that behavior appears secondary to its core role as a spam and malware distribution platform. Cutwail was the subject of multiple disruption and takedown efforts by researchers and law enforcement-adjacent defenders, reflecting its significance as one of the major spam botnets of its era.

Capabilities

  • Ddos
  • Defense Evasion
  • Initial Access
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 17, 2026
Feed role
C2
Host form
0 IP / 92 hostnames

Leading locations

  • US55
  • JP8
  • FR5
  • CA4
  • DE4
  • PL4
  • NL2
  • BE1
  • CN1
  • CZ1
  • FI1
  • GB1

Leading providers

  • Cloudflare, Inc.17
  • Amazon.com, Inc.6
  • Amazon.com, Inc.6
  • OVH SAS4
  • XServer Cloud Inc.4
  • Cloudflare London, LLC3

Infrastructure traits

  • Hosting 86
  • Anycast 26

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
TA544

En 2019, le botnet Cutwail distribue Dridex ID 1044 via des campagnes dโ€™hameรงonnage.

JabberZeuS

For many years, Cutwail has been among the top three most prolific spam botnets... versions of Cutwail are responsible for about 22 percent of the daily spam volumes worldwide. Security researchers have extensively dissected the technical machinery that powers Cutwail (a.k.a. โ€œPushdoโ€ and โ€œPandexโ€)...

GOLD ESSEX

"...distribution via spam emails from GOLD ESSEX's Cutwail botnet..."

MITRE ATT&CK

Cutwail in ATT&CK

18 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.