Russian APT 'Gamaredon' Hits Ukraine With Fierce Phishing
ID: c89afced-e20c-5649-8cba-40b40129f1f8
STIX ID: report--c89afced-e20c-5649-8cba-40b40129f1f8
Feed Name: Dark Reading
Gamaredon (Russia-aligned APT) has resumed focused espionage against Ukrainian government entities using spear-phishing, weaponized USB/network drives, and a refreshed toolset. ESET observed increased sophistication including Cloudflare subdomain/tunnel abuse for C2 obfuscation, HTML smuggling via XHTML attachments, HTA/LNK/VBScript/PowerShell loaders, and multiple new tools (PteroGraphin, PteroPSDoor, PteroDespair, PteroTickle, PteroQuark, PteroStew, PteroBox) used for persistence, lateral movement and exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
