logo

Stellar Discovery of A New Cluster of Andromeda/Gamarue C2

ID: ff9e7961-4a53-5e8d-8e79-e6b00abfe2e4

STIX ID: report--ff9e7961-4a53-5e8d-8e79-e6b00abfe2e4

Feed Name: Cybereason Blog

Threat Score
70/100

Date Published: 2024-12-03

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason observed an active Andromeda/Gamarue backdoor campaign targeting APAC manufacturing and logistics, using USB drop attacks and LNK-triggered rundll32 DLL execution to deploy droppers (trustedinstaller.exe) and backdoors that perform process injection and connect to a cluster of C2 servers (notably suckmycocklameavindustry.in and related IPs). The report provides IOCs (file hashes, domains, IPs, registry persistence keys), links to possible Turla activity (low–medium confidence), analysis of multiple cases including AutoIt masquerades and secondary malware (Pykspa), MITRE ATT&CK mappings, and detection/remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.