The Andromeda botnet, also tracked as Gamaru and Wauchos, operated for years as a modular Windows malware platform that steadily added stronger evasion, persistence, and command-and-control features. Analyses of versions including 2.7 through 2.10 show layered packing, anti-debugging and anti-VM checks, process injection and hollowing, watchdog-based self-repair, registry and autorun persistence, and encrypted HTTP communications using RC4, with later variants shifting to JSON-formatted C2 messages. The malware commonly spread through spam, phishing, compromised websites, illegal download portals, and exploit kits including Neutrino, Nuclear, Angler, and Rig, while using plug-ins for capabilities such as keylogging, form grabbing, rootkit functions, hidden TeamViewer access, and downloading additional malware.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
The Virus Bulletin review states that underground forum posts suggested Andromeda development stopped around 2017. The same review notes that a 2017 takedown effort and arrest of a suspected Belarusian administrator may have marked the botnet's end.
Avast reported that the analyzed newer Andromeda variant began spreading at the beginning of 2016. The variant relied on layered packing, custom encryption, anti-analysis protections, process injection into msiexec.exe, and RC4-encrypted HTTP C2 traffic.
Trend Micro reported that infrastructure centered on IP address 80.242.123.144, used in an Andromeda-to-GamaPoS campaign, had been active since the first week of May 2015. The campaign used spam documents and exploit-kit infections to download Andromeda.
In a 2015 campaign, Andromeda served as the initial access mechanism for distributing GamaPoS point-of-sale malware, primarily against U.S. businesses. After infection, Andromeda deployed tools including PsExec, mimikatz, .NET downloaders, and in some cases the GamaPoS payload.
The latest Andromeda version discussed in the review, version 2.10, was first seen in 2015. This version switched its C2 message format to JSON while continuing to use RC4 encryption and moved more anti-analysis logic into the payload.
Andromeda, also known as Gamaru or Wauchos, was first discovered in the wild in 2011. Multiple references describe it as a modular HTTP-based botnet that surfaced around that year.
Fortinet's ART team reported that the Andromeda botnet was downloading a newly discovered .NET multifunctional botnet called Proteus. Proteus supported proxying, cryptocurrency mining, account checking, keylogging, and downloading additional malware.
A new Andromeda 2.7 version was observed in the wild with stronger self-defense, persistence, and stealth features than earlier variants. Its protocol and encryption changes also rendered older Andromeda IPS/IDS signatures ineffective.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
virusbulletin.com
Open sourcefortinet.com
Open sourceblog.avast.com
Open sourcevirusbulletin.com
Open sourcedocuments.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.