Oh no! The operators of the Andromeda botnet had let their cute domain suckmycocklameavindustry[.]in expire and now suckmycocklameavindustry[.]in is owned by the Russia-linked Turla group, which is using it to deliver malware to targets in Ukraine https://www.mandiant.com/resources/blog/turla-galaxy-opportunity
(State actors piggybacking on botnet infrastructure isn't new. The NSA has done something similar in the past https://arstechnica.com/information-technology/2015/01/nsa-secretly-hijacked-existing-malware-to-spy-on-n-korea-others/ )
Turla: A Galaxy of Opportunity | Mandiant

Mandiant