PULSE NAME
Gamaredon APT targets Ukrainian government agencies in new campaign
WHITE Gamaredon Group AlienVault 2022-09-19 Modified: 2022-10-19
53
IOCs
HIGH VOLUME
Cisco Talos discovered Gamaredon APT activity targeting users in Ukraine with malicious LNK files distributed in RAR archives. The campaign, part of an ongoing espionage operation observed as recently as August 2022, aims to deliver information-stealing malware to Ukrainian victim machines and makes heavy use of multiple modular PowerShell and VBScript (VBS) scripts as part of the infection chain. The infostealer is a dual-purpose malware that includes capabilities for exfiltrating specific file types and deploying additional binary and script-based payloads on an infected endpoint.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (4 / 53 total)
All hostname FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
URL http://155.138.252.221/get.php 2022-09-19
URL http://45.77.237.252/get.php 2022-09-19
URL http://heato.ru/index.php 2022-09-19
URL http://motoristo.ru/get.php 2022-09-19