ANDROMEDA — Malware Profile
ANDROMEDA is commodity malware that was widespread in the early 2010's and continues to be observed in infections across a wide variety of industries. During the 2022 C0026 campaign, threat actors re-registered expired ANDROMEDA C2 domains to spread malware to select targets in Ukraine.
MITRE ATT&CK techniques (7)
- T1036.005 Match Legitimate Resource Name or Location
- T1036.008 Masquerade File Type
- T1055 Process Injection
- T1071.001 Web Protocols
- T1091 Replication Through Removable Media
- T1105 Ingress Tool Transfer
- T1547.001 Registry Run Keys / Startup Folder
Attributed threat actors
- Operation C-Major machine-inferred link