Russia-linked Gamaredon APT infected thousands of government computers in Ukraine

Russia-linked Gamaredon APT infected thousands of government computers in Ukraine

Computer Emergency Response Team of Ukraine (CERT-UA) has published a technical analysis of cyber-espionage attacks against Ukraine by the Kremlin-linked threat actor Gamaredon.

According to the Ukrainian cyber defenders, Gamaredon (aka Armageddon, UAC-0010, Shuckworm) may have infected several thousands of government computers as part of the group’s operations since the start of Russia’s invasion. Furthermore, the threat actor appears to have carried out at least one destructive attack against Ukrainian information infrastructure facilities.

The initial infection vectors used by the threat actors include emails and messages sent via messaging services like Telegram, WhatsApp, or Signal. The messages typically contain an HTM or HTA file that, when opened, activates the infection chain.

Once the victim opens the malicious attachments, PowerShell scripts and malware (most often the “GammaSteel” information stealer) are downloaded and executed on the victim's device.

Upon gaining initial access, the threat actor proceeds to exfiltrate files, typically within a timeframe of 30 to 50 minutes. The infected computer can contain more than 80-120 infected files, and the attackers can re-infected a computer if at least one malicious file remains on the machine, CERT-UA notes.

Last month, Gamaredon was observed targeting government entities, and organizations in Ukraine's military and security intelligence sectors, using updated malware tools.


Back to the list

Latest Posts

Cyber Security Week in Review: March 07, 2025

Cyber Security Week in Review: March 07, 2025

In brief: Russian crypto exchange Garantex seized by police, the US charges Chinese hackers, major Western chatbots are spreading Russian propaganda, and more.
7 March 2025
US сharges APT27 and i-Soon hackers with cyberattacks on entities across globe

US сharges APT27 and i-Soon hackers with cyberattacks on entities across globe

The US authorities are offering a reward of up to $10 million for information leading to the capture and conviction of the suspects.
6 March 2025
North Korean IT workers creating fake personas on GitHub to secure remote jobs

North Korean IT workers creating fake personas on GitHub to secure remote jobs

Many of the fake personas are crafted with reused GitHub accounts and portfolio content.
5 March 2025