Tainted drive appears to be source of malware attack on Western military mission in Ukraine
ID: ebd9282e-a114-5957-b6dc-586acd102472
STIX ID: report--ebd9282e-a114-5957-b6dc-586acd102472
Feed Name: The Record from Recorded Future News
Threat Score
Symantec researchers reported that Russia‑linked Gamaredon (Shuckworm/BlueAlpha) deployed an updated GammaSteel infostealer in Feb–Mar against a Ukraine‑based Western military mission via an infected removable drive; the campaign used a complex multi‑stage chain, enhanced obfuscation, and legitimate services (with prior use of Cloudflare Tunnels), suggesting growing sophistication in the group's espionage operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
