AndroMut

Aliases: Gelup

First seen
2019-06-01 00:00:00
Malware type
downloader
Family
Malware family
Profile updated
2026-07-07 12:54:07

Targeted industries: financial-services technology-and-telecommunications

Context

According to Proofpoint, AndroMut is a new downloader malware written in C++ that Proofpoint researchers began observing in the wild in June 2019. The “Andro” part of the name comes from some of the pieces which bear resemblance to another downloader malware known as Andromeda [1] and “Mut” is based off a mutex that the analyzed sample creates: “mutshellmy777”.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Andromut_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Andromut (report)
  • ptsecurity.com — Operation Ta505 Part3 (report)
  • Trend Micro — Tech Brief Latest Spam Campaigns From Ta505 Now Using New Malware Tools Gelup And Flowerpippi (report)
  • proofpoint.com — Ta505 Begins Summer Campaigns New Pet Malware Downloader Andromut Uae South (report)
  • blueliv.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
  • outpost24.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)

External references