17 July 2023

Russia-linked Gamaredon APT infected thousands of government computers in Ukraine


Russia-linked Gamaredon APT infected thousands of government computers in Ukraine

Computer Emergency Response Team of Ukraine (CERT-UA) has published a technical analysis of cyber-espionage attacks against Ukraine by the Kremlin-linked threat actor Gamaredon.

According to the Ukrainian cyber defenders, Gamaredon (aka Armageddon, UAC-0010, Shuckworm) may have infected several thousands of government computers as part of the group’s operations since the start of Russia’s invasion. Furthermore, the threat actor appears to have carried out at least one destructive attack against Ukrainian information infrastructure facilities.

The initial infection vectors used by the threat actors include emails and messages sent via messaging services like Telegram, WhatsApp, or Signal. The messages typically contain an HTM or HTA file that, when opened, activates the infection chain.

Once the victim opens the malicious attachments, PowerShell scripts and malware (most often the “GammaSteel” information stealer) are downloaded and executed on the victim's device.

Upon gaining initial access, the threat actor proceeds to exfiltrate files, typically within a timeframe of 30 to 50 minutes. The infected computer can contain more than 80-120 infected files, and the attackers can re-infected a computer if at least one malicious file remains on the machine, CERT-UA notes.

Last month, Gamaredon was observed targeting government entities, and organizations in Ukraine's military and security intelligence sectors, using updated malware tools.


Back to the list

Latest Posts

Cyber Security Week in Review: November 1, 2024

Cyber Security Week in Review: November 1, 2024

In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
1 November 2024
North Korean hackers caught collaborating with Play ransomware

North Korean hackers caught collaborating with Play ransomware

The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
31 October 2024
Large-scale phishing campaign targeting Ukraine's taxpayers

Large-scale phishing campaign targeting Ukraine's taxpayers

The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
30 October 2024