FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad
ID: 08a983dc-8d83-5ad3-86af-64e3e9628ca2
STIX ID: report--08a983dc-8d83-5ad3-86af-64e3e9628ca2
Feed Name: Sekoia.io Blog (archive)
**Sekoia.io TDR analysis of Gamaredon’s GammaLoad:** This report analyzes GammaLoad, a three-stage chain of VBScript and obfuscated PowerShell loaders used by the FSB-linked Gamaredon intrusion set to stage and deploy the GammaSteel stealer; it documents registry-based C2 caching under HKCU\Console, use of Dead Drop Resolvers (Telegraph/Telegram/Check-Host) to retrieve C2, the in-memory execution and ADS dropper behaviors, scheduled-task persistence for periodic execution, and provides sample file hashes and network IOCs observed during active interaction with the actor’s infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
