ANDROMEDA

S1074

Malware.View on attack.mitre.org

About this malware

ANDROMEDA is commodity malware that was widespread in the early 2010's and continues to be observed in infections across a wide variety of industries. During the 2022 C0026 campaign, threat actors re-registered expired ANDROMEDA C2 domains to spread malware to select targets in Ukraine.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service.

T1036.008
Masquerade File Type

ANDROMEDA has been delivered through a LNK file disguised as a folder.

T1055
Process Injection

ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions.

T1071.001
Web Protocols

ANDROMEDA has the ability to make GET requests to download files from C2.

T1091
Replication Through Removable Media

ANDROMEDA has been spread via infected USB keys.

T1105
Ingress Tool Transfer

ANDROMEDA can download additional payloads from C2.

T1547.001
Registry Run Keys / Startup Folder

ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant Suspected Turla Campaign February 2023 Open source
    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.