Gamaredon in 2024: Cranking out spearphishing campaigns against Ukraine with an evolved toolset
ID: b6eb5294-e962-53e6-85cf-e949e44555b0
STIX ID: report--b6eb5294-e962-53e6-85cf-e949e44555b0
Feed Name: WeLiveSecurity (ESET Research)
**ESET Research details Gamaredon’s 2024 activities:** the Russia-aligned APT refocused exclusively on Ukrainian governmental targets, ramped up spearphishing (malicious archives, HTML smuggling, LNK/PowerShell via Cloudflare), introduced six new PowerShell/VBScript tools and upgraded multiple existing malware components for stealth, persistence and lateral movement, and hid much of its C2 behind Cloudflare tunnels, DoH and third-party platforms; a full white paper and IoC set are published for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
