AndroMut, also known as Gelup, is a Windows downloader associated with TA505 activity observed in 2019. It has been used in phishing-driven intrusion chains to retrieve and execute second-stage malware, most notably the FlawedAmmyy remote access trojan. Campaigns using AndroMut targeted organizations in multiple regions, including South Korea and financial institutions in Singapore, the United Arab Emirates, and the United States.
AndroMut is implemented in C++ and incorporates multiple anti-analysis and defense-evasion features. Reported behaviors include runtime resolution of Windows API functions by hash, encrypted or obfuscated strings, sandbox and emulator checks, debugger detection, and explicit clearing of sensitive data from memory. It also establishes persistence on infected systems, including through scheduled-task-based execution and autorun mechanisms.
For command and control, AndroMut stores an encrypted configuration containing connection parameters and cryptographic material, constructs its network endpoint from that configuration, and exchanges AES-256-encrypted JSON data over HTTP POST. Supported tasking includes beaconing, self-removal, downloading and executing additional payloads, and self-update. The malware appears to have functioned primarily as a first-stage downloader within TA505 operations rather than as a standalone access platform.
AndroMut is notable as part of TA505’s broader transition from large-scale banking trojan and ransomware delivery toward modular downloaders, backdoors, and more targeted enterprise intrusion activity. Low-confidence similarities to Andromeda and QtLoader have been noted, but AndroMut is treated as a distinct malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June 2019, TA505 appears to have introduced yet another new downloader malware, AndroMut... Proofpoint research has observed AndroMut download malware referred to as “FlawedAmmyy.”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 semble avoir procédé à la distribution de ses charges malveillantes uniquement par campagnes de courriels d’hameçonnage... L’unique vecteur d’infection pour l’instant connu du mode opératoire TA505 demeure le courriel d’hameçonnage incluant une pièce jointe ou un lien malveillant.
The HTM or HTML attachments contained links to the download of an Office file. Depending on the specific case, the delivered Word or Excel file used macros to execute a Msiexec command that would download and execute either the FlawedAmmyy loader or AndroMut.
Depending on user privileges the malware creates persistence by either scheduling a task that executes a created LNK file in the Recycle Bin or via the “Registry run” method.
301 - Similar to “300” command, but executes the file using “cmd[.]exe [/]C”
Depending on the specific case, the delivered Word or Excel file used macros to execute a Msiexec command that would download and execute either the FlawedAmmyy loader or AndroMut.
AndroMut decrypts strings in one of two ways: The encrypted string is base64-decoded then decrypted with AES-256 in ECB mode... The encrypted string is stored as a stack string.
Depending on the specific case, the delivered Word or Excel file used macros to execute a Msiexec command that would download and execute either the FlawedAmmyy loader or AndroMut.
Checks for sandboxing by looking for the following process names: cmdvirth.exe (COMODO) SbieSvc.exe (Sandboxie) VMSrvc.exe (Virtual PC) xenservice.exe (Xen) Checks for mouse movement Checks for the Wine emulator by looking for the “HKEY_CURRENT_USER\SOFTWARE\Wine” subkey in the Registry
Checks for debuggers by looking for debugging flags set in the NtGlobalFlag field of its Process Environment Block (PEB) Checks for debuggers by setting a “Puleg” mutex, setting the HANDLE_FLAG_PROTECT_FROM_CLOSE flag on the mutex handle, then trying to close the handle
Checks for sandboxing by looking for the following process names: cmdvirth.exe (COMODO) SbieSvc.exe (Sandboxie) VMSrvc.exe (Virtual PC) xenservice.exe (Xen) Checks for mouse movement Checks for the Wine emulator by looking for the “HKEY_CURRENT_USER\SOFTWARE\Wine” subkey in the Registry
Checks for debuggers by looking for debugging flags set in the NtGlobalFlag field of its Process Environment Block (PEB) Checks for debuggers by setting a “Puleg” mutex, setting the HANDLE_FLAG_PROTECT_FROM_CLOSE flag on the mutex handle, then trying to close the handle
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A downloader malware previously distributed by TA505.
A new C++ downloader malware observed in June 2019 that uses API hashing, string encryption, anti-analysis checks, persistence via scheduled task or Registry Run key, and HTTP POST JSON-based C2. It can download and execute payloads in multiple ways, update itself, or remove itself. In the observed campaigns it delivered FlawedAmmyy.
Downloader apparently specific to TA505, notable for anti-analysis mechanisms.
Downloader apparently specific to TA505, notable for anti-analysis mechanisms and observed mainly in summer 2019.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.