Latest gambit for Gamaredon: Fake Ukraine troop movement documents with malicious links
ID: caa49d1d-2515-50bb-b4e8-f595bf6db734
STIX ID: report--caa49d1d-2515-50bb-b4e8-f595bf6db734
Feed Name: The Record from Recorded Future News
Cisco Talos reports an ongoing campaign—active since at least November 2024—attributed with medium confidence to Russian state-backed Gamaredon that uses phishing emails and PowerShell scripts to download a ZIP containing the Remcos remote administration/spying tool from servers in Russia and Germany; Remcos enables surveillance, browser credential theft, and can run as a legitimate Windows process to evade AV, and the activity is part of broader Russian cyber operations targeting Ukraine.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
