PULSE NAME
The Russian Shadow in Eastern Europe: Ukrainian MOD Campaign
WHITE Gamaredon AlienVault 2019-04-24 Modified: 2019-04-25
19
IOCs
MEDIUM VOLUME
Few days after the publication of our technical article related to the evidence of possible APT28 interference in the Ukrainian elections, we spotted another signal of a sneakier on-going operation. This campaign, instead, seems to be linked to another Russian hacking group: Gamaredon. The Gamaredon APT was first spotted in 2013 and in 2015, when researchers at LookingGlass shared the details of a cyber espionage operation tracked as Operation Armageddon, targeting other Ukrainian entities. Their “special attention” on Eastern European countries was also confirmed by CERT-UA, the Ukrainian Computer Emergency Response Team.
Indicators of Compromise (3 / 19 total)
All FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname librework.ddns.net 2019-04-24
hostname bitwork.ddns.net 2019-04-24
hostname lisingrout.ddns.net 2019-04-25