logo

Gamaredon’s Spear-Phishing Assault On Ukraine’s Military

ID: bbdadd24-ca01-5e46-9ad1-625140226061

STIX ID: report--bbdadd24-ca01-5e46-9ad1-625140226061

Feed Name: Cyble Blog

Threat Score
90/100

Date Published: 2024-09-06

Date Updated: 2026-07-20

...
...

Cyble Research and Intelligence Labs (CRIL) identified an active Gamaredon APT spear-phishing campaign targeting Ukrainian military personnel that delivers malicious XHTML attachments containing obfuscated JavaScript; the script drops a RAR with an LNK that invokes mshta.exe to fetch remote .tar archives hosted via TryCloudflare, and the report provides numerous SHA256 hashes and malicious URLs as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.