Two massive spam delivering over 210,000 emails flooded the inboxes of Italian users with files carrying the Andromeda malware.
The spam campaign took place on July 4-5 and July 11-14, and according to security researchers at Palo Alto Networks, the scammers were deliberately targeting Italian users.
In fact, based on indications in the email messages, 97.4 percent of all spam was targeted at Italian users.

Clues include the spam email subjects (which were all in Italian), the name of the attached file (also in Italian), and the email address used to send the spam (spoofed addresses belonging to Aruba.it, an Italian Web hosting provider, and other Italian domains).
All files attached to these emails spread Andromeda, a malware dropper that adds infected computers to the Andromeda botnet.
The technical capabilities of this malware allow the people behind this botnet to transfer other types of malware to infect their victims with the click of a button from the control panel.
This includes keyloggers, rootkits, infostealers, RATs, as well as any other Andromeda module they might want, with any functionality.
The Andromeda malware and botnet appeared in 2011 and have been used to spread other types of malware families, such as the GamaPoS malware.
The good news is that Andromeda is not that common and is not even part of the top 10 malware list for June.
Now we just have to wait for July's results!
