Cutwail
Cutwail is a prolific spam botnet, also known as Pushdo and Pandex. The content describes it as one of the world’s most active spam botnets and states that after the Rustock takedown it became the top spam botnet, with M86 Security estimating that versions of Cutwail were responsible for about 22 percent of daily global spam volume. Its alleged principal developer and renter is identified by the handle “Google.” The botnet was used extensively for bulk spam operations and was rented to other spammers, including members of the SpamIt rogue pharmacy affiliate ecosystem. The content states that Google rented Cutwail to SpamIt members and earned substantial revenue both from SpamIt commissions and from renting the botnet. Cutwail’s spam engine was known on spam forums as 0bulk Psyche Evolution, and clients were provided a web interface in Russian or English to create and manage spam campaigns. According to the content, Cutwail evolved from pharmacy spam, stock spam, and OEM software spam into a major malware delivery platform. It was used to distribute malicious attachments carrying ZeuS and SpyEye variants, and by 2009 the JabberZeuS crew had hired Cutwail to distribute malicious emails used in cyber heists. Recent campaigns described in the content used lures involving airline ticket orders, ACH payments, Facebook notifications, scanned documents, and geographically tailored ransomware emails spoofing national law enforcement agencies. The content also states that Waledac malware was recently sent from the Cutwail botnet. The content links Cutwail operationally and financially to SpamIt and attributes operation of the botnet to the actor using the alias “Google.” It also mentions an associate using the handle “Eagle,” described as the technical director in Google’s operation.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- RU
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spam botnet referenced historically in connection with the domain used to distribute malware.
Botnet operator competing to provide spam infrastructure to SpamIt affiliates and rivaled by SPM/Srizbi in the spam software market.
A major spam botnet operation rented to affiliates for large-scale spam campaigns, initially promoting rogue pharmacies and pirated software, and later distributing malware and ransomware-themed malicious spam.
A botnet used to distribute Waledac malware in spam campaigns.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.