PULSE NAME
Analysis of APT-C-53 (Gamaredon) Attack on Ukrainian Government Agencies
WHITE APT-C-53 (Gamaredon) AlienVault 2025-09-01 Modified: 2025-10-01
16
IOCs
MEDIUM VOLUME
APT-C-53, also known as Gamaredon, is a Russian state-sponsored threat group active since 2013, targeting Ukrainian government and military entities. The group has upgraded its attack techniques, focusing on dynamic cloud-based C2 infrastructure and targeted delivery of cloud storage tools. In 2025, they conducted high-density intelligence theft activities against Ukrainian government agencies. The attack chain involves dynamic changes in infrastructure, abuse of Microsoft Dev Tunnels, and sophisticated data exfiltration techniques. The group employs white-listed domain camouflage, domain shadowing, and weaponization of cloud tunnel services to evade detection. Their data theft process includes registry-based persistence, multi-stage payload delivery via Cloudflare Workers, and exfiltration through legitimate cloud tools like Dropbox.
Indicators of Compromise (16)
All FileHash-MD5 URL domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 023429e53d32fa29e4c7060c8f3d37db 2025-09-01
FileHash-MD5 0459531e3cbc84ede6a1a75846a87495 2025-09-01
FileHash-MD5 67896b57a4dcf614fb22283c130ab78b 2025-09-01
FileHash-MD5 9258a427c782cd8d7dcf25dc0d661239 2025-09-01
FileHash-MD5 98b540aeb2e2350f74ad36ddb4d3f66f 2025-09-01
FileHash-MD5 d2c551812c751332b74b0517e76909f2 2025-09-01
FileHash-MD5 f3deebe705478ec1a4ec5538ac3669cb 2025-09-01
URL http://nandayo.ru/srgssdfsf 2025-09-01
domain bulam.ru 2025-09-01
domain fulagam.ru 2025-09-01
domain litanq.ru 2025-09-01
domain nandayo.ru 2025-09-01
email megamarket.ua@p9tm15n7-80.euw.devtunnels.ms 2025-09-01
email wise.com@p9tm15n7-80.euw.devtunnels.ms 2025-09-01
hostname 80.euw.devtunnels.ms 2025-09-01
hostname euw.devtunnels.ms 2025-09-01