← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Analysis of APT-C-53 (Gamaredon) Attack on Ukrainian Government Agencies
APT-C-53, also known as Gamaredon, is a Russian state-sponsored threat group active since 2013, targeting Ukrainian government and military entities. The group has upgraded its attack techniques, focusing on dynamic cloud-based C2 infrastructure and targeted delivery of cloud storage tools. In 2025, they conducted high-density intelligence theft activities against Ukrainian government agencies. The attack chain involves dynamic changes in infrastructure, abuse of Microsoft Dev Tunnels, and sophisticated data exfiltration techniques. The group employs white-listed domain camouflage, domain shadowing, and weaponization of cloud tunnel services to evade detection. Their data theft process includes registry-based persistence, multi-stage payload delivery via Cloudflare Workers, and exfiltration through legitimate cloud tools like Dropbox.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 023429e53d32fa29e4c7060c8f3d37db | — | 2025-09-01 | |
| FileHash-MD5 | 0459531e3cbc84ede6a1a75846a87495 | — | 2025-09-01 | |
| FileHash-MD5 | 67896b57a4dcf614fb22283c130ab78b | — | 2025-09-01 | |
| FileHash-MD5 | 9258a427c782cd8d7dcf25dc0d661239 | — | 2025-09-01 | |
| FileHash-MD5 | 98b540aeb2e2350f74ad36ddb4d3f66f | — | 2025-09-01 | |
| FileHash-MD5 | d2c551812c751332b74b0517e76909f2 | — | 2025-09-01 | |
| FileHash-MD5 | f3deebe705478ec1a4ec5538ac3669cb | — | 2025-09-01 | |
| URL | http://nandayo.ru/srgssdfsf | — | 2025-09-01 | |
| domain | bulam.ru | — | 2025-09-01 | |
| domain | fulagam.ru | — | 2025-09-01 | |
| domain | litanq.ru | — | 2025-09-01 | |
| domain | nandayo.ru | — | 2025-09-01 | |
| megamarket.ua@p9tm15n7-80.euw.devtunnels.ms | — | 2025-09-01 | ||
| wise.com@p9tm15n7-80.euw.devtunnels.ms | — | 2025-09-01 | ||
| hostname | 80.euw.devtunnels.ms | — | 2025-09-01 | |
| hostname | euw.devtunnels.ms | — | 2025-09-01 |