Gamaredon APT Targeting Ukraine with New Variants
ID: e4bc1885-8a38-50c8-87f1-a0f6d1f6e5bb
STIX ID: report--e4bc1885-8a38-50c8-87f1-a0f6d1f6e5bb
Feed Name: Cyble Blog
Threat Score
**Executive Summary:** Cyble observed a renewed Gamaredon (Russia-linked APT) campaign targeting Ukrainian national security forces via spear-phishing documents that use template-injection to download payloads from attacker-controlled C2 servers; the report provides IoCs (hashes, domains, IP), describes the infection flow and TTPs, and notes limited endpoint detections indicating stealthy operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
