AndroMut
Aliases: Gelup
- First seen
- 2019-06-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Profile updated
- 2026-07-07 12:54:07
Targeted industries: financial-services technology-and-telecommunications
Context
According to Proofpoint, AndroMut is a new downloader malware written in C++ that Proofpoint researchers began observing in the wild in June 2019. The “Andro” part of the name comes from some of the pieces which bear resemblance to another downloader malware known as Andromeda [1] and “Mut” is based off a mutex that the analyzed sample creates: “mutshellmy777”.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Andromut_Auto (yara-rule)
Reports & references
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- intel471.com — A Brief History Of Ta505 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Andromut (report)
- ptsecurity.com — Operation Ta505 Part3 (report)
- Trend Micro — Tech Brief Latest Spam Campaigns From Ta505 Now Using New Malware Tools Gelup And Flowerpippi (report)
- proofpoint.com — Ta505 Begins Summer Campaigns New Pet Malware Downloader Andromut Uae South (report)
- blueliv.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
- outpost24.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)