National Cyber Warfare Foundation (NCWF)

Gamaredon Group


0 user ratings
2024-06-18 15:21:27
blscott

 - archive -- 

Gamaredon Group

MITRE:  G0047

Gamaredon Group is a suspected Russian cyber espionage threat group that has targeted military, NGO, judiciary, law enforcement, and non-profit organizations in Ukraine since at least 2013. The name Gamaredon Group comes from a misspelling of the word \\\"Armageddon\\\", which was detected in the adversary\\\'s early campaigns.In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia\\\'s Federal Security Service (FSB) Center 18.

The Gamaredon Group is an APT (Advanced Persistent Threat) that has been active since at least 2014, targeting various industries including government agencies and financial institutions in Europe and North America. They are known for their sophisticated tactics such as spear-phishing emails with malicious attachments or links to compromised websites, exploiting vulnerabilities in software and operating systems, and using customized tools and techniques to evade detection by security solutions. Gamaredon Group has been linked to various cyber espionage campaigns aimed at stealing sensitive information such as confidential documents, credentials, and intellectual property.\\
\\
Techniques, tactics and practices: \\
\\
The Gamaredon Group is an advanced persistent threat that has been active since at least 2014. They use various sophisticated tactics such as spear-phishing emails with malicious attachments or links to compromised websites, exploiting vulnerabilities in software and operating systems, using customized tools and techniques to evade detection by security solutions, targeting various industries including government agencies and financial institutions in Europe and North America. They have been linked to cyber espionage campaigns aimed at stealing sensitive information such as confidential documents, credentials, and intellectual property.

Unit 42 threat researchers have recently observed a threat
group distributing new, custom developed malware. We have labelled this threat
group the Gamaredon Group and our research shows that the Gamaredon Group has
been active since at least 2013. In the past, the Gamaredon Group has relied
heavily on off-the-shelf tools. Our new research shows the Gamaredon Group have
made a shift to custom-developed malware. We believe this shift indicates the
Gamaredon Group have improved their technical capabilities. (Lookingglass) The
Lookingglass Cyber Threat Intelligence Group (CTIG) has been tracking an
ongoing cyber espionage campaign named “Operation Armageddon”. The name was
derived from multiple Microsoft Word documents used in the attacks. “Armagedon”
(spelled incorrectly) was found in the “Last Saved By” and “Author” fields in
multiple Microsoft Word documents. Although continuously developed, the
campaign has been intermittently active at a small scale, and uses
unsophisticated techniques. The attack timing suggests the campaign initially
started due to Ukraine’s decision to accept the Ukraine-­European
Union Association Agreement (AA). The agreement was designed to improve
economic integrations between Ukraine and the European Union. Russian leaders
publicly stated that they believed this move by Ukraine directly threatened
Russia’s national security. Although initial steps to join the Association
occurred in March 2012, the campaign didn’t start until much later (mid2013),
as Ukraine and the EU started to more actively move towards the agreement.
Russian actors began preparing for attacks in case Ukraine finalized the AA.
The earliest identified modification timestamp of malware used in this campaign
is June 26, 2013. A group of files with modification timestamps between August
12 and September 16, 2013 were used in the first wave of spear-phishing
attacks, targeting government officials prior to the 10th Yalta Annual Meeting:
“Changing Ukraine in a Changing World: Factors of Success.”

 

 Other names

ACTINIUM, Actinium, Aqua Blizzard, Armageddon, Blue Otso,
BlueAlpha, Callisto, DEV-0157, G0047, Gamaredon Group, IRON TILDEN, Operation
“STEADY#URSA”, PRIMITIVE BEAR, SectorC08, Shuckworm, Trident Ursa, UAC-0010,
Winterflounder,

 

 First seen- 2013

 Sponsor

State-sponsored, FSB Centre 18: Centre for Information
Security (TsIB)

 Targets

Albania, Australia, Austria, Bangladesh, Brazil, Canada,
Chile, China, Colombia, Croatia, Denmark, Georgia, Germany, Guatemala,
Honduras, India, Indonesia, Iran, Israel, Italy, Japan, Kazakhstan, Latvia,
Malaysia, Netherlands, Nigeria, Norway, Pakistan, Papua New Guinea, Poland,
Portugal, Romania, Russia, South Africa, South Korea, Spain, Sweden, Turkey,
United Kingdom, United States, Ukraine, Vietnam,

 Target categories

Defense, Government, Law enforcement, NGOs,

Tools

Aversome
infector (category: Malware)


type: Backdoor, Worm

(Kaspersky) In this case, we observed an interesting new second stage payload
that includes spreading capabilities, that we call “Aversome infector”. This
malware seems to have been developed to maintain a strong persistence in the
target network and to move laterally by infecting Microsoft Word and Excel
documents on external drives.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a404ba82-faac-42e4-86d6-2f52e3984272

https://securelist.com/apt-trends-report-q1-2020/96826/





BoneSpy (category:
Malware)


type: Reconnaissance, Backdoor, Info stealer

(Lookout) The BoneSpy family showed evidence of continuous development between
roughly January and October 2022, after which samples began using consistent
lure theming and code structure. Earlier samples from between January and
September 2022 used a variety of trojanized apps such as battery charge
monitoring apps, photo-gallery apps, a fake Samsung Knox app, and trojanized
Telegram apps. Later, Gamaredon largely shifted to using trojanized, fully
functional Telegram samples titled as “Beta” versions.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=10958f58-9776-4d97-82f9-fbf37312d0d3

https://www.lookout.com/threat-intelligence/article/gamaredon-russian-android-surveillanceware





DessertDown (category:
Malware)


type: Downloader, Loader

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=45bb2926-764b-4b09-8af9-f69124724c78

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/





DilongTrash (category:
Malware)


typ: Downloader, Loader



No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6e70d20f-b915-47d7-9f28-d7da6f853f5b

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/

https://malpedia.caad.fkie.fraunhofer.de/details/win.dilongtrash





DinoTrain (category:
Malware)


type: Downloader, Loader

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=cd1e5a26-55bf-4386-9959-d133204014a7

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/

https://malpedia.caad.fkie.fraunhofer.de/details/win.dinotrain





EvilGnome (category:
Malware)


type: Backdoor

(Intezer) A Linux backdoor implant.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5499a91e-6e35-417c-a804-2f12173718f0

https://intezer.com/blog-evilgnome-rare-malware-spying-on-linux-desktop-users/

https://malpedia.caad.fkie.fraunhofer.de/details/elf.evilgnome





FRAUDROP (category:
Malware)


type: Backdoor

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8d3449bc-91d8-4721-9046-f4243ec2bb8c

https://cybersecurity.att.com/blogs/labs-research/alien-labs-2019-analysis-of-threat-groups-molerats-and-apt-c-37





Gamaredon (category:
Malware)


type: Reconnaissance, Backdoor, Info stealer, Downloader

(Palo Alto) The custom-developed malware is fully featured an includes these
capabilities: • A mechanism for downloading and executing additional payloads
of their choice • The ability to scan system drives for specific file types •
The ability to capture screenshots • The ability to remotely execute commands
on the system in the user’s security context

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5b6ffec9-8c1f-48a2-a83c-f24e02de8510

https://unit42.paloaltonetworks.com/unit-42-title-gamaredon-group-toolset-evolution/





GammaDrop (category:
Malware)


type: Dropper

(Recorded Future) GammaDrop is an HTML application HTA payload used to
execute and set the persistence of an embedded \'GammaLoad\' payload.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b8ce3138-976a-46a9-8b6d-08202c91162e

https://go.recordedfuture.com/hubfs/reports/cta-ru-2024-1205.pdf





GammaLoad (category:
Malware)


type: Backdoor

(Recorded Future) GammaLoad is a custom backdoor used by BlueAlpha, with
variants in both PowerShell and VBScript. In this campaign, the VBScript
variant was observed.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a3a6ff62-22d2-4c62-8984-1b625f97a9bb

https://go.recordedfuture.com/hubfs/reports/cta-ru-2024-1205.pdf





GammaSteel (category:
Malware)


type: Info stealer

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6abbcbe3-3b74-4df8-a4e3-19f9ea226b59

https://go.recordedfuture.com/hubfs/reports/cta-ru-2024-1205.pdf





ObfuBerry (category:
Malware)


type: Downloader, Loader

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=eef9b13d-a63c-426a-b5c4-ff58480289bd

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/





ObfuMerry (category:
Malware)


type: Downloader, Loader

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=98f81056-84dd-4442-ad5e-7197746bc83e

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/





PlainGnome (category:
Malware)


type: Reconnaissance, Backdoor, Info stealer

(Lookout) PlainGnome consists of a two-stage deployment in which a very minimal
first stage drops a malicious APK once it’s installed. While the first and
second stages use some variation on the Telegram package name, the actual
functionality presented to the user is essentially the same as that observed in
previous BoneSpy samples using the “image gallery” theme. This lure theme
continued through most of PlainGnome’s deployment throughout 2024.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2f6eb326-1cd4-4e06-9521-b49bd22fe1ec

https://www.lookout.com/threat-intelligence/article/gamaredon-russian-android-surveillanceware





PowerPunch (category:
Malware)


type: Downloader, Loader

(Microsoft) PowerPunch is executed from within PowerShell as a one-line
command, encoded using Base64. These binaries also exhibit features that rely
on data from the compromised host to inform encryption of the next stage.
PowerPunch also provides an excellent example of this. The VolumeSerialNumber
of the host serves as the basis for a multibyte XOR key. The key is applied to
an executable payload downloaded directly from adversary infrastructure,
allowing for an encryption key unique to the target host. Ultimately, a
next-stage executable is remotely retrieved and dropped to disk prior to
execution.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2653faee-fcff-4add-8934-b0ae27606c61

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/

https://attack.mitre.org/software/S0685/





Pteranodon (category:
Malware)


type: Backdoor, Info stealer, Downloader

(Palo Alto) Pteranodon is a custom backdoor which is capable of the following
tasks: • Capturing screenshots at a configurable interval and uploading them to
the attacker • Downloading and executing additional files • Executing arbitrary
commands on the system

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ef780da4-a57f-4a89-b653-dd7798dfef03

https://unit42.paloaltonetworks.com/unit-42-title-gamaredon-group-toolset-evolution/

https://threatpost.com/gamaredon-apt-toolset-ukraine/152568/



https://www.vkremez.com/2019/01/lets-learn-deeper-dive-into-gamaredon.html

https://cert.gov.ua/news/42

https://cert.gov.ua/news/46

https://blog.threatstop.com/russian-apt-gamaredon-group

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/

https://attack.mitre.org/software/S0147/

https://malpedia.caad.fkie.fraunhofer.de/details/win.pteranodon

https://otx.alienvault.com/browse/pulses?q=tag:Pteranodon





QuietSieve (category:
Malware)


type: Info stealer, Exfiltration

(Microsoft) The QuietSieve malware family refers to a series of
heavily-obfuscated .NET binaries specifically designed to steal information
from the target host.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fe59dd39-ff4d-4f89-a5d4-89ceb6235b7c

https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/

https://attack.mitre.org/software/S0686/

https://malpedia.caad.fkie.fraunhofer.de/details/win.quietsieve





Resetter (category:
Malware)




No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=872bd484-b7cb-41ba-88f2-0aab6c6e5d85

https://unit42.paloaltonetworks.com/unit-42-title-gamaredon-group-toolset-evolution/





RMS (category:
Tools)


type: Backdoor, Info stealer

CyberInt states that Remote Manipulator System (RMS) is a legitimate tool
developed by Russian organization TektonIT and has been observed in campaigns
conducted by TA505 as well as numerous smaller campaigns likely attributable to
other, disparate, threat actors. In addition to the availability of commercial
licenses, the tool is free for non-commercial use and supports the remote
administration of both Microsoft Windows and Android devices.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b263aa0-475c-413f-b618-ed55c6546690

https://rmansys.ru/remote-access/

https://malpedia.caad.fkie.fraunhofer.de/details/win.rms





SUBTLE-PAWS (category:
Malware)


type: Backdoor

(Securonix) An interesting campaign leveraging a new SUBTLE-PAWS
PowerShell-based backdoor has been identified targeting Ukraine which follows
stealthy tactics to evade detection and spreads by infecting USB drives.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=307adb06-a320-4718-8579-21ae7b3a9ea4

https://www.securonix.com/blog/security-advisory-steadyursa-attack-campaign-targets-ukraine-military/

https://malpedia.caad.fkie.fraunhofer.de/details/ps1.subtle_paws





UltraVNC (category:
Tools)


type: Backdoor

An open-source remote administration tool for Microsoft Windows.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=37598bc7-4222-4408-bb42-48800ddf2f8e

https://symantec-blogs.broadcom.com/blogs/threat-intelligence/chafer-latest-attacks-reveal-heightened-ambitions



TTP



































T1583

T1583.001

[Gamaredon Group] has registered multiple domains to facilitate payload staging
and C2.(Citation: Microsoft Actinium February 2022)(Citation: Unit 42 Gamaredon
February 2022)



T1583.003

[Gamaredon Group] has used VPS hosting providers for infrastructure outside of
Russia.(Citation: unit42_gamaredon_dec2022)



T1071

T1071.001

[Gamaredon Group] has used HTTP and HTTPS for C2 communications.(Citation: Palo
Alto Gamaredon Feb 2017)(Citation: TrendMicro Gamaredon April 2020)(Citation:
ESET Gamaredon June 2020)(Citation: Symantec Shuckworm January 2022)(Citation:
CERT-EE Gamaredon January 2021)(Citation: Unit 42 Gamaredon February
2022)(Citation: unit42_gamaredon_dec2022)



T1119

[Gamaredon Group] has deployed scripts on compromised systems that
automatically scan for interesting documents.(Citation: ESET Gamaredon June
2020)



T1020

[Gamaredon Group] has used modules that automatically upload gathered documents
to the C2 server.(Citation: ESET Gamaredon June 2020)



T1547

T1547.001

[Gamaredon Group] tools have registered Run keys in the registry to give
malicious VBS files persistence.(Citation: TrendMicro Gamaredon April
2020)(Citation: ESET Gamaredon June 2020)(Citation: CERT-EE Gamaredon January
2021)(Citation: unit42_gamaredon_dec2022)



T1059

T1059.001

[Gamaredon Group] has used obfuscated PowerShell scripts for staging.(Citation:
Microsoft Actinium February 2022)



T1059.003

[Gamaredon Group] has used various batch scripts to establish C2 and download
additional files. [Gamaredon Group]\'s backdoor malware has also been written to
a batch file.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: ESET Gamaredon
June 2020)(Citation: CERT-EE Gamaredon January 2021)(Citation: Unit 42
Gamaredon February 2022)



T1059.005

[Gamaredon Group] has embedded malicious macros in document templates, which
executed VBScript. [Gamaredon Group] has also delivered Microsoft Outlook VBA
projects with embedded macros.(Citation: TrendMicro Gamaredon April
2020)(Citation: ESET Gamaredon June 2020)(Citation: CERT-EE Gamaredon January
2021)(Citation: Microsoft Actinium February 2022)(Citation: Secureworks IRON
TILDEN Profile)



T1005

[Gamaredon Group] has collected files from infected systems and uploaded them
to a C2 server.(Citation: ESET Gamaredon June 2020)



T1039

[Gamaredon Group] malware has collected Microsoft Office documents from mapped
network drives.(Citation: ESET Gamaredon June 2020)



T1025

A [Gamaredon Group] file stealer has the capability to steal data from newly
connected logical volumes on a system, including USB drives.(Citation: Palo
Alto Gamaredon Feb 2017)(Citation: ESET Gamaredon June 2020)



T1001

[Gamaredon Group] has used obfuscated VBScripts with randomly generated
variable names and concatenated strings.(Citation: unit42_gamaredon_dec2022)



T1491

T1491.001

[Gamaredon Group] has left taunting images and messages on the victims\'
desktops as proof of system access.(Citation: CERT-EE Gamaredon January 2021)



T1140

[Gamaredon Group] tools decrypted additional payloads from the C2. [Gamaredon
Group] has also decoded base64-encoded source code of a downloader.(Citation:
TrendMicro Gamaredon April 2020)(Citation: ESET Gamaredon June 2020)
Additionally, [Gamaredon Group] has decoded Telegram content to reveal the IP
address for C2 communications.(Citation: unit42_gamaredon_dec2022)



T1561

T1561.001

[Gamaredon Group] has used tools to delete files and folders from victims\'
desktops and profiles.(Citation: CERT-EE Gamaredon January 2021)



T1568

[Gamaredon Group] has incorporated dynamic DNS domains in its
infrastructure.(Citation: Unit 42 Gamaredon February 2022)



T1568.001

[Gamaredon Group] has used fast flux DNS to mask their command and control
channel behind rotating IP addresses.(Citation: unit42_gamaredon_dec2022)



T1480

[Gamaredon Group] has used geoblocking to limit downloads of the malicious file
to specific geographic locations.(Citation: unit42_gamaredon_dec2022)



T1041

A [Gamaredon Group] file stealer can transfer collected files to a hardcoded C2
server.(Citation: Palo Alto Gamaredon Feb 2017)



T1083

[Gamaredon Group] macros can scan for Microsoft Word and Excel files to inject
with additional malicious macros. [Gamaredon Group] has also used its backdoors
to automatically list interesting files (such as Office documents) found on a
system.(Citation: ESET Gamaredon June 2020)(Citation: Unit 42 Gamaredon
February 2022)



T1564

T1564.003

[Gamaredon Group] has used hidcon to run batch files in a hidden console
window.(Citation: Unit 42 Gamaredon February 2022)



T1562

T1562.001

[Gamaredon Group] has delivered macros which can tamper with Microsoft Office
security settings.(Citation: ESET Gamaredon June 2020)



T1070

T1070.004

[Gamaredon Group] tools can delete files used during an operation.(Citation:
TrendMicro Gamaredon April 2020)(Citation: Symantec Shuckworm January
2022)(Citation: CERT-EE Gamaredon January 2021)



T1105

[Gamaredon Group] has downloaded additional malware and tools onto a
compromised host.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: TrendMicro
Gamaredon April 2020)(Citation: ESET Gamaredon June 2020)(Citation: Microsoft
Actinium February 2022) For example, [Gamaredon Group] uses a backdoor script
to retrieve and decode additional payloads once in victim
environments.(Citation: unit42_gamaredon_dec2022)



T1559

T1559.001

[Gamaredon Group] malware can insert malicious macros into documents using a
Microsoft.Office.Interop object.(Citation: ESET Gamaredon June 2020)



T1534

[Gamaredon Group] has used an Outlook VBA module on infected systems to send
phishing emails with malicious attachments to other employees within the
organization.(Citation: ESET Gamaredon June 2020)



T1036

T1036.005

[Gamaredon Group] has used legitimate process names to hide malware including
svchosst.(Citation: Unit 42 Gamaredon February 2022)



T1112

[Gamaredon Group] has removed security settings for VBA macro execution by
changing registry values HKCU\\Software\\Microsoft\\Office\\\\\\Security\\VBAWarnings
and
HKCU\\Software\\Microsoft\\Office\\\\\\Security\\AccessVBOM.(Citation:
ESET Gamaredon June 2020)(Citation: CERT-EE Gamaredon January 2021)



T1106

[Gamaredon Group] malware has used CreateProcess to launch additional malicious
components.(Citation: ESET Gamaredon June 2020)



T1027

[Gamaredon Group] has delivered self-extracting 7z archive files within
malicious document attachments.(Citation: ESET Gamaredon June 2020)



T1027.001

[Gamaredon Group] has obfuscated .NET executables by inserting junk
code.(Citation: ESET Gamaredon June 2020)



T1027.004

[Gamaredon Group] has compiled the source code for a downloader directly on the
infected system using the built-in Microsoft.CSharp.CSharpCodeProvider
class.(Citation: ESET Gamaredon June 2020)



T1027.010

[Gamaredon Group] has used obfuscated or encrypted scripts.(Citation: ESET
Gamaredon June 2020)(Citation: Microsoft Actinium February 2022)



T1588

T1588.002

[Gamaredon Group] has used various legitimate tools, such as `mshta.exe` and
[Reg](https://attack.mitre.org/software/S0075), and services during
operations.(Citation: unit42_gamaredon_dec2022)



T1137

[Gamaredon Group] has inserted malicious macros into existing documents,
providing persistence when they are reopened. [Gamaredon Group] has loaded the
group\'s previously delivered VBA project by relaunching Microsoft Outlook with
the /altvba option, once the Application.Startup event is received.(Citation:
ESET Gamaredon June 2020)



T1120

[Gamaredon Group] tools have contained an application to check performance of
USB flash drives. [Gamaredon Group] has also used malware to scan for removable
drives.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: ESET Gamaredon June
2020)



T1566

T1566.001

[Gamaredon Group] has delivered spearphishing emails with malicious attachments
to targets.(Citation: TrendMicro Gamaredon April 2020)(Citation: ESET Gamaredon
June 2020)(Citation: CERT-EE Gamaredon January 2021)(Citation: Microsoft
Actinium February 2022)(Citation: Unit 42 Gamaredon February 2022)(Citation:
Secureworks IRON TILDEN Profile)(Citation: unit42_gamaredon_dec2022)



T1057

[Gamaredon Group] has used tools to enumerate processes on target hosts
including Process Explorer.(Citation: Symantec Shuckworm January
2022)(Citation: Unit 42 Gamaredon February 2022)



T1021

T1021.005

[Gamaredon Group] has used VNC tools, including UltraVNC, to remotely interact
with compromised hosts.(Citation: Symantec Shuckworm January 2022)(Citation:
Microsoft Actinium February 2022)(Citation: Unit 42 Gamaredon February 2022)



T1053

T1053.005

[Gamaredon Group] has created scheduled tasks to launch executables after a
designated number of minutes have passed.(Citation: ESET Gamaredon June
2020)(Citation: CERT-EE Gamaredon January 2021)(Citation: Microsoft Actinium
February 2022)(Citation: unit42_gamaredon_dec2022)



T1113

[Gamaredon Group]\'s malware can take screenshots of the compromised computer
every minute.(Citation: ESET Gamaredon June 2020)



T1608

T1608.001

[Gamaredon Group] has registered domains to stage payloads.(Citation: Microsoft
Actinium February 2022)(Citation: Unit 42 Gamaredon February 2022)



T1218

T1218.005

[Gamaredon Group] has used `mshta.exe` to execute malicious files.(Citation:
Symantec Shuckworm January 2022)(Citation: unit42_gamaredon_dec2022)



T1218.011

[Gamaredon Group] malware has used rundll32 to launch additional malicious
components.(Citation: ESET Gamaredon June 2020)



T1082

A [Gamaredon Group] file stealer can gather the victim\'s computer name and
drive serial numbers to send to a C2 server.(Citation: Palo Alto Gamaredon Feb
2017)(Citation: TrendMicro Gamaredon April 2020)(Citation: CERT-EE Gamaredon
January 2021)



T1016

T1016.001

[Gamaredon Group] has tested connectivity between a compromised machine and a
C2 server using [Ping](https://attack.mitre.org/software/S0097) with commands
such as `CSIDL_SYSTEM\\cmd.exe /c ping -n 1`.(Citation: Symantec Shuckworm
January 2022)



T1033

A [Gamaredon Group] file stealer can gather the victim\'s username to send to a
C2 server.(Citation: Palo Alto Gamaredon Feb 2017)



T1080

[Gamaredon Group] has injected malicious macros into all Word and Excel
documents on mapped network drives.(Citation: ESET Gamaredon June 2020)



T1221

[Gamaredon Group] has used DOCX files to download malicious DOT document
templates and has used RTF template injection to download malicious
payloads.(Citation: Proofpoint RTF Injection) [Gamaredon Group] can also inject
malicious macros or remote templates into documents already present on
compromised systems.(Citation: TrendMicro Gamaredon April 2020)(Citation: ESET
Gamaredon June 2020)(Citation: CERT-EE Gamaredon January 2021)(Citation:
Microsoft Actinium February 2022)(Citation: Unit 42 Gamaredon February
2022)(Citation: Secureworks IRON TILDEN Profile)



T1204

T1204.001

[Gamaredon Group] has attempted to get users to click on a link pointing to a
malicious HTML file leading to follow-on malicious content.(Citation:
unit42_gamaredon_dec2022)



T1204.002

[Gamaredon Group] has attempted to get users to click on Office attachments
with malicious macros embedded.(Citation: TrendMicro Gamaredon April
2020)(Citation: ESET Gamaredon June 2020)(Citation: Symantec Shuckworm January
2022)(Citation: CERT-EE Gamaredon January 2021)(Citation: Microsoft Actinium
February 2022)(Citation: Unit 42 Gamaredon February 2022)(Citation: Secureworks
IRON TILDEN Profile)(Citation: unit42_gamaredon_dec2022)



T1102

[Gamaredon Group] has used GitHub repositories for downloaders which will be
obtained by the group\'s .NET executable on the compromised system.(Citation:
ESET Gamaredon June 2020)



T1102.003

[Gamaredon Group] has used Telegram Messenger content to discover the IP
address for C2 communications.(Citation: unit42_gamaredon_dec2022)



T1047

[Gamaredon Group] has used WMI to execute scripts used for discovery and for
determining the C2 IP address.(Citation: CERT-EE Gamaredon January
2021)(Citation: unit42_gamaredon_dec2022)






Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
Actinum
Blue Otso
ACTINIUM
Shuckworm
Primitive Bear
APT-C-53
Armageddon
Winterflounder
G0047
IRON TILDEN
Temp.Armageddon
DEV-0157
Aqua Blizzard
UAC-0010
BlueAlpha
Trident Ursa
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.