Gamaredon’s Spear-Phishing Assault On Ukraine’s Military
ID: bbdadd24-ca01-5e46-9ad1-625140226061
STIX ID: report--bbdadd24-ca01-5e46-9ad1-625140226061
Feed Name: Cyble Blog
Threat Score
Cyble Research and Intelligence Labs (CRIL) identified an active Gamaredon APT spear-phishing campaign targeting Ukrainian military personnel that delivers malicious XHTML attachments containing obfuscated JavaScript; the script drops a RAR with an LNK that invokes mshta.exe to fetch remote .tar archives hosted via TryCloudflare, and the report provides numerous SHA256 hashes and malicious URLs as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
