Cutwail, also known as Pushdo and Pandex, was one of the most prolific spam botnets of its era and at times ranked among the top global sources of unsolicited email. It functioned both as a large-scale spam distribution platform and as a malware delivery service rented to other criminal operators. Reporting has associated its principal operator with the handle “Google,” and linked the botnet commercially to the SpamIt rogue-pharmacy affiliate ecosystem, where access to the botnet was rented to spammers and other cybercriminal customers. Cutwail initially specialized in high-volume spam campaigns, including rogue-pharmacy and stock spam, and later evolved into a broader malware spam platform. It was used to distribute banking trojans and other crimeware, including ZeuS- and SpyEye-related payloads, and was also observed delivering Waledac malware. Campaign themes included financial transaction lures, social-network notifications, travel-related messages, and document-themed attachments. Later activity included geographically tailored ransomware delivery using spoofed law-enforcement themes. Operationally, Cutwail provided customers with a managed spam service and campaign administration interface, enabling rented use by multiple affiliates. Its ecosystem included a downloader component used to deploy the botnet malware onto infected Windows systems. Infection and spam-delivery operations supported large-scale malicious email distribution worldwide, and the botnet was repeatedly cited as responsible for a substantial share of daily global spam volume. Cutwail’s demonstrated behaviors include initial compromise through malware deployment, persistence on infected hosts, large-scale spam-based malware delivery, and post-compromise use of victim machines for criminal distribution operations. Its activity was primarily financially motivated, centered on monetizing botnet access, spam delivery, malware distribution, and related cybercrime services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spam botnet referenced historically in connection with the domain used to distribute malware.
Botnet operator competing to provide spam infrastructure to SpamIt affiliates and rivaled by SPM/Srizbi in the spam software market.
A major spam botnet operation rented to affiliates for large-scale spam campaigns, initially promoting rogue pharmacies and pirated software, and later distributing malware and ransomware-themed malicious spam.
A botnet used to distribute Waledac malware in spam campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.