Cutwail, also known as Pandex and closely associated with Pushdo, is a long-running Windows spam botnet and spambot malware family that emerged around 2007 and became one of the most prolific global sources of junk email. It was commonly installed by the Pushdo downloader and operated through centralized command-and-control infrastructure that supplied message content and recipient lists, after which infected hosts sent spam directly over SMTP and reported delivery statistics and errors back to operators. Cutwail was widely used as a rentable criminal service by multiple spam groups and played a major role in the underground spam economy, including campaigns tied to online pharmacy spam and large-scale malware distribution.
Beyond bulk spam operations, Cutwail functioned as a malware delivery platform for other criminal ecosystems. It has been documented distributing or helping distribute malware including Gameover Zeus, CryptoLocker, Dridex, FakeRean, and other payloads delivered through broader downloader chains involving Pushdo and related infrastructure. It was also used in malspam campaigns targeting financial institutions and other organizations, including region-specific campaigns such as those delivering Ursnif in Japan. Some Cutwail variants and related operations used process-injection techniques, and the broader Pushdo/Cutwail ecosystem incorporated host profiling and security-product awareness to improve payload delivery and operational resilience.
Cutwail primarily targeted Microsoft Windows systems. At its height it was estimated to control hundreds of thousands to millions of infected hosts and to account for a substantial share of worldwide spam volume. Although best known for spam distribution, the botnet was also observed conducting distributed denial-of-service activity in at least one period, though that behavior appears secondary to its core role as a spam and malware distribution platform. Cutwail was the subject of multiple disruption and takedown efforts by researchers and law enforcement-adjacent defenders, reflecting its significance as one of the major spam botnets of its era.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
En 2019, le botnet Cutwail distribue Dridex ID 1044 via des campagnes d’hameçonnage.
For many years, Cutwail has been among the top three most prolific spam botnets... versions of Cutwail are responsible for about 22 percent of the daily spam volumes worldwide. Security researchers have extensively dissected the technical machinery that powers Cutwail (a.k.a. “Pushdo” and “Pandex”)...
"...distribution via spam emails from GOLD ESSEX's Cutwail botnet..."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
This episode tells the stories of some of the worlds biggest spamming botnets. We’ll talk about the botnets Rustock, Waledac, and Cutwail.
At the peak, during one 24-hour period the XBL detected nearly 300,000 IP addresses that were infected with Festi, out of a total of 1-million that were infected with some sort of spam-sending bot.
This episode tells the stories of some of the worlds biggest spamming botnets. We’ll talk about the botnets Rustock, Waledac, and Cutwail.
When infections are successful, the pages then redirect visitors to websites that silently install a malware cocktail that includes the Asprox malware.
Asprox zombies have recently been blessed with a tool that sniffs out potentially vulnerable sites running Microsoft's Active Server Pages and then tries to commandeer them using SQL injections.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A large spam delivery botnet discussed as one of the biggest spamming botnets, associated in the transcript sources with pharmacy spam operations.
Spam botnet used to distribute Upatre and Gameover Zeus, thereby facilitating CryptoLocker delivery.
Spam-focused botnet historically used to distribute malicious software via large-scale spam campaigns.
Spam botnet used as a distribution mechanism for Dridex campaigns (briefly resumed in 2020).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.