ANDROMEDA

MITRE ATT&CK: S1074 View on attack.mitre.org

Aliases: B106-Gamarue, B67-SS-Gamarue, Gamarue, b66, ANDROMEDA

First seen
2010-01-01 00:00:00
Malware type
botnet, loader, trojan
Family
Malware family
Operating systems
windows
Related IoCs
156 (118 malicious)
Last IoC activity
2026-09-02 00:35:48
Profile updated
2026-07-07 12:47:39

Targeted industries: financial-services government-and-public-sector manufacturing technology-and-telecommunications

Targeted regions: country_code:ua

Context

ANDROMEDA is commodity malware that was widespread in the early 2010's and continues to be observed in infections across a wide variety of industries. During the 2022 C0026 campaign, threat actors re-registered expired ANDROMEDA C2 domains to spread malware to select targets in Ukraine.

Recent IoC activity

118 malicious indicators in Maltiverse are attributed to ANDROMEDA (S1074). The 20 most recently updated:

Detection coverage

  • 1 YARA rules
  • 172 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Process Injection (attack-pattern)
  • Web Protocols (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Replication Through Removable Media (attack-pattern)

Used by threat actors

  • C0026 (campaign)

Detection rules

  • MALPEDIA_Win_Andromeda_Auto (yara-rule)

Reports & references

  • proofpoint.com — Proofpoint Operation Transparent Tribe Threat Insight En (report)
  • Kaspersky — 109552 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
  • redcanary.com — Intelligence Insights November 2021 (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • Mandiant — Turla Galaxy Opportunity (report)
  • malware.dontneedcoffee.com — Eyeglanceru (report)
  • resource.redcanary.com — 2021 Threat Detection Report (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Andromeda (report)
  • eternal-todo.com — Yet Another Andromeda Gamarue Analysis (report)
  • resources.infosecinstitute.com — Andromeda Bot Analysis (report)
  • trellix.com — Cyberattacks Targeting Ukraine Increase (report)
  • 0xebfe.net — Fooled By Andromeda (report)
  • resources.infosecinstitute.com — Andromeda Bot Analysis Part Two (report)
  • blog.avast.com — Andromeda Under The Microscope (report)
  • shadowserver.org — Has The Sun Set On The Necurs Botnet (report)
  • blog.morphisec.com — Andromeda Tactics Analyzed (report)
  • Microsoft — Microsoft Teams Up With Law Enforcement And Other Partners To Disrupt Gamarue Andromeda (report)
  • virusbulletin.com — Andromeda 2 7 Features (report)
  • byte-atlas.blogspot.ch — Kf Andromeda Bruteforcing (report)
  • CrowdStrike — How To Remediate Hidden Malware Real Time Response (report)
  • virusbulletin.com — Review Evolution Andromeda Over Years We Say Goodbye (report)
  • europol.europa.eu — Andromeda Botnet Dismantled In International Cyber Operation (report)
  • eternal-todo.com — Andromeda Gamarue Loves Json (report)
  • MITRE ATT&CK — S1074 (report)

External references