PULSE NAME
Russian-Backed Gamaredon's Spyware Variants
WHITE BITSecurity 2023-02-02 Modified: 2023-03-04
173
IOCs
HIGH VOLUME
"UAC-0010 group's ongoing activity is characterized by a multi-step download approach and executing payloads of the spyware used to maintain control over infected hosts," the SCPC said. "For now, the UAC-0010 group uses GammaLoad and GammaSteel spyware in their campaigns." GammaLoad is a VBScript dropper malware engineered to download next-stage VBScript from a remote server. GammaSteel is a PowerShell script that's capable of conducting reconnaissance and executing additional commands. The goal of the attacks is geared more towards espionage and information theft rather than sabotage, the agency noted. The SCPC also emphasized the "insistent" evolution of the group's tactics by redeveloping its malware toolset to stay under the radar, calling Gamaredon a "key cyber threat."
Indicators of Compromise (3 / 173 total)
All FileHash-MD5 FileHash-SHA256 URL domain hostname FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 59948e7126a2927a53af0593f85dad2f5ae5c6e0 2023-02-02
FileHash-SHA1 62d4677fcf600ac0c4933bd80dec255868827e00 2023-02-02
FileHash-SHA1 9f5fe4bab163de5eedb995beed21c75578284fa4 2023-02-02