← Back to Pulse Feed
PULSE DETAIL
"UAC-0010 group's ongoing activity is characterized by a multi-step download approach and executing payloads of the spyware used to maintain control over infected hosts," the SCPC said. "For now, the UAC-0010 group uses GammaLoad and GammaSteel spyware in their campaigns."
GammaLoad is a VBScript dropper malware engineered to download next-stage VBScript from a remote server. GammaSteel is a PowerShell script that's capable of conducting reconnaissance and executing additional commands.
The goal of the attacks is geared more towards espionage and information theft rather than sabotage, the agency noted. The SCPC also emphasized the "insistent" evolution of the group's tactics by redeveloping its malware toolset to stay under the radar, calling Gamaredon a "key cyber threat."
Indicators of Compromise (3 / 173 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 59948e7126a2927a53af0593f85dad2f5ae5c6e0 | — | 2023-02-02 | |
| FileHash-SHA1 | 62d4677fcf600ac0c4933bd80dec255868827e00 | — | 2023-02-02 | |
| FileHash-SHA1 | 9f5fe4bab163de5eedb995beed21c75578284fa4 | — | 2023-02-02 |