PULSE NAME
Russian-Backed Gamaredon's Spyware Variants
WHITE BITSecurity 2023-02-02 Modified: 2023-03-04
173
IOCs
HIGH VOLUME
"UAC-0010 group's ongoing activity is characterized by a multi-step download approach and executing payloads of the spyware used to maintain control over infected hosts," the SCPC said. "For now, the UAC-0010 group uses GammaLoad and GammaSteel spyware in their campaigns." GammaLoad is a VBScript dropper malware engineered to download next-stage VBScript from a remote server. GammaSteel is a PowerShell script that's capable of conducting reconnaissance and executing additional commands. The goal of the attacks is geared more towards espionage and information theft rather than sabotage, the agency noted. The SCPC also emphasized the "insistent" evolution of the group's tactics by redeveloping its malware toolset to stay under the radar, calling Gamaredon a "key cyber threat."
Indicators of Compromise (45 / 173 total)
All FileHash-MD5 FileHash-SHA256 URL domain hostname FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 00fe49d9fde36aace2e9c35962ac11f8595b8452d84ba02f4511754ced831d66 2023-02-02
FileHash-SHA256 1113fc222132460fe481ed0a62fb3fe1426bc920cdb01d334c7a7a6ef952dfee 2023-02-02
FileHash-SHA256 143cc8dade3ac835c9114333e05544b52dc57a1273cbdd4aca38253a710c92ab 2023-02-02
FileHash-SHA256 1928ea04a52ea5ced87305cc001e693385ecbb8d3b4c64c1288d4b223de841dd 2023-02-02
FileHash-SHA256 1b59868b460359f46c6ae0a01b6f34c89a33b79992a03573fc40bd3c501cbea4 2023-02-02
FileHash-SHA256 24fe5b916433ae295685dddcc5c808fb4cd3d3a2c3d999b721f4e650773b1ed4 2023-02-02
FileHash-SHA256 2cb17eb3450b4cfad148427986410cda69d47a124a7dea43c577a55569ff3761 2023-02-02
FileHash-SHA256 2dfef7c52c05c3b88818edd7764ef1f1d41c1450918441e6a5d8b1518b80ac3e 2023-02-02
FileHash-SHA256 430206ba1fbd0c869b71608ad1808febfb067e086d0b330225b5afcddc1af352 2023-02-02
FileHash-SHA256 452d40893e9973ec5e4779ea830320d80999b09a36113b7d86de866a02823a3c 2023-02-02
FileHash-SHA256 564aba6e5366347b1e522b2af7a46fa54e6d23af4ce17b2dd3a5d45d925c7aa4 2023-02-02
FileHash-SHA256 6cb0ef2538cd074fbcccca5a96bb21538529220eeeeaca63e06a18cbbc6a9eb4 2023-02-02
FileHash-SHA256 6cccc179db19c405cc313f60d3bb09e00f7b273ec3c6ddf03ae4cba3fcac961d 2023-02-02
FileHash-SHA256 6f2004a5b3f4f1c84c0e0e08181cfb8bbc0f50617e58d57cecddf4789587880a 2023-02-02
FileHash-SHA256 788dc18de55d73027011a0b109b4b795e6ae485bdda7dd07deecab6af386170c 2023-02-02
FileHash-SHA256 79c340f1d8c78b96d4e92a78d9c407494769df79ab491dfe2b1955f26af4e388 2023-02-02
FileHash-SHA256 7d2c607bb9627e14d572356ff653b587ea0d7f7b2c1f4ab45bb979b81f9369ae 2023-02-02
FileHash-SHA256 7e3cfa63b31ed9e4606e43b29a704924a27b62d6b9a1360b462d9998deed549f 2023-02-02
FileHash-SHA256 81d8c20a19e1c2c3e5bfd6f8a39499321f42b07f6b94c9e0bb98fd6cfd4355a8 2023-02-02
FileHash-SHA256 88dc766c51f20c93b670bd67b543b70e8d627c9afc041ee74aa6b64c59eb1c7d 2023-02-02
FileHash-SHA256 968f841df2fd5b7458d15569b756088691e6d4a04e5f6f22df1c773e1fe35129 2023-02-02
FileHash-SHA256 9b81fbe9f7157e7873862fe7fabd9df5fdb8197bf1cc01b5e34cbebf5ff0de13 2023-02-02
FileHash-SHA256 9c724d00f28b3453e283e5b0ef5c8455bb61d4c902c53cfb38f07ffb4e17e18d 2023-02-02
FileHash-SHA256 a0c2429616e7bf8a36951d45cbc72a1eab4d4a1a1e8266753a75bdd683737814 2023-02-02
FileHash-SHA256 a2361ca9fd84fd41d62628e2310317831f47f8e973c2bda24dadc0972fb983d6 2023-02-02
FileHash-SHA256 afcb200cf4a646397f67c37d396cd5573db2575ae945b3251dfb6d285d1e6724 2023-02-02
FileHash-SHA256 bcb63de0b16c449b054982ad1d4c23810a396e061ae45801df4d64acf4e82674 2023-02-02
FileHash-SHA256 c172c8733c92d914574290eb46d8a6c1b49387d8d4dceafc3e13d953395c9710 2023-02-02
FileHash-SHA256 c19dbecf59908f530a63705af62a3596531f7eecbb971a2926670fb4c0697a2c 2023-02-02
FileHash-SHA256 c82728665fafb66828f3fe2d9ee28b2e670e958abc1f5dda6c5e460db2502207 2023-02-02
FileHash-SHA256 cb81b6516f13844c653a9fcbbbeed099dde5be307ec66523be7678d577dca477 2023-02-02
FileHash-SHA256 dcb69e1c9a6bff950481cf1f493b3e9665133e9afae528f0d38d72e83607a6d0 2023-02-02
FileHash-SHA256 f1f4ed4122564c90b473617d9989a2a90af1d93c4b75c8cfecd564ff71f803a0 2023-02-02
FileHash-SHA256 f2f6077597d1fdb84bbb35aebd169af522767bc3a6aae58e778c429626f376a3 2023-02-02
FileHash-SHA256 f628fa53fc3f91c1d812246291b3a188904ab091c735e8dc7ed644103a0eb5c6 2023-02-02
FileHash-SHA256 f96489503934b654e00cbd0c48845d66aaf3b91f5bd53fd05d7ecfc48a66dc20 2023-02-02
FileHash-SHA256 05457a790782542d3f16c9b8368a077b458ff7349856e6da541223a51e94b9c8 2023-02-02
FileHash-SHA256 2708b9f8a196c50c8c6d6001af5b02e3c5d113e1977a686319eae7652ecbc1d3 2023-02-02
FileHash-SHA256 3442724f36fcaa1822bdafc3417e6bc7488898c4acbc73f0114ffeb6a3604164 2023-02-02
FileHash-SHA256 521c8345351144437033b41dfb5e4878c3b3a7ade4e2d0ccdcc5699d0b4d3ac6 2023-02-02
FileHash-SHA256 72028cff34d33e26bf01e4bf63c8b977ece33b3809bd6dd075bcff343895dc4b 2023-02-02
FileHash-SHA256 91e9325dd4972c0d40becfff6e65399c46aeb210a3b9a1f75d453cc8fe87d09c 2023-02-02
FileHash-SHA256 b10bc0bb30b3c1d0c404d3a902ccebc425f23cb5a66c02104739f226c77b5816 2023-02-02
FileHash-SHA256 cf919033a2a4f76a4b78499be027090a0a7980a2f536df53eebb2140478abeb7 2023-02-02
FileHash-SHA256 d8236c841b07c933d4de0ef9ed854902f6aae73b83137d9ffbe29fb879aa094f 2023-02-02