Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:49:05 UTC Home > List all groups > List all tools > List all groups using tool AndroMut Tool: AndroMut Names AndroMut Category Malware Type Downloader Description (Proofpoint) In June 2019, TA505 appears to have introduced yet another new downloader malware, AndroMut, which has some similarities in code and behavior to Andromeda, a long-established malware family. Proofpoint research has observed AndroMut download malware referred to as “FlawedAmmyy.” Information Malpedia Last change to this tool card: 24 April 2021 Download this tool card in JSON format All groups using tool AndroMut Changed Name Country Observed APT groups   FIN11 [Unknown] 2016-Mar 2025   TA505, Graceful Spider, Gold Evergreen 2006-Nov 2022 2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c0076597-3d86-4828-9c99-d8a9eefd9ee1 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c0076597-3d86-4828-9c99-d8a9eefd9ee1 Page 1 of 1