Cutwail is a Windows spambot malware family and large-scale spam botnet active since approximately 2007. Also known as Pandex, it is closely associated with Pushdo, a distinct downloader commonly used to install Cutwail. Its principal function is to send unsolicited and malicious email from compromised computers, supporting commercial spam, phishing, and distribution of banking trojans and ransomware. Operators have rented its spam-delivery infrastructure to multiple criminal groups.
Cutwail uses centralized command-and-control infrastructure. Infected hosts receive message content and recipient lists, send email directly over SMTP, and report delivery statistics and errors to their controllers. Cutwail samples have demonstrated process-injection functionality, and the family has also been observed downloading additional malware, including FakeRean rogue security software. The botnet conducted distributed denial-of-service activity against hundreds of websites in February 2010, although spam delivery remains its defining function.
Cutwail has supported campaigns distributing Gameover Zeus, Ursnif/Gozi, and Dridex, including infection chains that subsequently installed CryptoLocker. Malicious messages have used invoice, order-confirmation, billing, and financial-service lures, with malicious attachments or links. Cutwail itself has also been delivered through compromised websites that redirect visitors to malware-installation infrastructure.
Cutwail-A and Cutwail-B variants have supported geographically differentiated campaigns, including extensive Japanese-language malspam and activity targeting European countries. TA544, also known as NARW Spider, has been linked to Cutwail-based delivery operations targeting Japan. These campaigns targeted banking customers and other financial-service users through downstream malware; the credential theft and financial fraud capabilities belong to those payloads rather than necessarily to Cutwail itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
En 2019, le botnet Cutwail distribue Dridex ID 1044 via des campagnes d’hameçonnage.
For many years, Cutwail has been among the top three most prolific spam botnets... versions of Cutwail are responsible for about 22 percent of the daily spam volumes worldwide. Security researchers have extensively dissected the technical machinery that powers Cutwail (a.k.a. “Pushdo” and “Pandex”)...
"...distribution via spam emails from GOLD ESSEX's Cutwail botnet..."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
This episode tells the stories of some of the worlds biggest spamming botnets. We’ll talk about the botnets Rustock, Waledac, and Cutwail.
At the peak, during one 24-hour period the XBL detected nearly 300,000 IP addresses that were infected with Festi, out of a total of 1-million that were infected with some sort of spam-sending bot.
This episode tells the stories of some of the worlds biggest spamming botnets. We’ll talk about the botnets Rustock, Waledac, and Cutwail.
When infections are successful, the pages then redirect visitors to websites that silently install a malware cocktail that includes the Asprox malware.
Asprox zombies have recently been blessed with a tool that sniffs out potentially vulnerable sites running Microsoft's Active Server Pages and then tries to commandeer them using SQL injections.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A spam botnet used to distribute malicious email and deliver banking trojans and ransomware. No specific downstream malware families are named.
A large spam delivery botnet discussed as one of the biggest spamming botnets, associated in the transcript sources with pharmacy spam operations.
Spam botnet used to distribute Upatre and Gameover Zeus, thereby facilitating CryptoLocker delivery.
Spam-focused botnet historically used to distribute malicious software via large-scale spam campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.