logo

Latest gambit for Gamaredon: Fake Ukraine troop movement documents with malicious links

ID: caa49d1d-2515-50bb-b4e8-f595bf6db734

STIX ID: report--caa49d1d-2515-50bb-b4e8-f595bf6db734

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-05-01

...
...

Cisco Talos reports an ongoing campaign—active since at least November 2024—attributed with medium confidence to Russian state-backed Gamaredon that uses phishing emails and PowerShell scripts to download a ZIP containing the Remcos remote administration/spying tool from servers in Russia and Germany; Remcos enables surveillance, browser credential theft, and can run as a legitimate Windows process to evade AV, and the activity is part of broader Russian cyber operations targeting Ukraine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.