Gamaredon X Turla collab
ID: 34938f11-71ac-591f-9f5b-9b4ff7a6ca6b
STIX ID: report--34938f11-71ac-591f-9f5b-9b4ff7a6ca6b
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET describes the first observed technical collaboration between Russian-aligned APTs Gamaredon and Turla in Ukraine, where Gamaredon-deployed PowerShell tools (PteroGraphin/PteroOdd/PteroPaste) were used to restart and install Turla’s Kazuar backdoor (v2 and v3) on selected high-value machines; the report provides timelines, code-level details, IoCs (hashes, domains, IPs), and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
