Summary:
Researcher are warning about the Gamaredon hacking group, a Russian state-sponsored cyber-espionage group. Gamaredon conducts rapid attacks, stealing data from breached systems in less than an hour.[/subscribe_to_unlock_form]
Summary:
Researcher are warning about the Gamaredon hacking group, a Russian state-sponsored cyber-espionage group. Gamaredon conducts rapid attacks, stealing data from breached systems in less than an hour.[emaillocker id="1283"]
The group typically initiates attacks by sending malicious emails or messages via messaging apps like Telegram, WhatsApp, or Signal. They trick victims into opening attachments disguised as Microsoft Word or Excel documents. Once opened, PowerShell scripts and malware (often 'GammaSteel') are downloaded and executed on the victim's device. Gamaredon also modifies Microsoft Office Word templates to embed malicious macros, which can spread the malware to other systems. The PowerShell script targets browser cookies with session data, allowing the hackers to take over accounts protected by two-factor authentication.The 'GammaSteel' malware targets specific file extensions, including .doc, .docx, .xls, .xlsx, .rtf, .odt, .txt, .jpg, .jpeg, .pdf, .ps1, .rar, .zip, .7z, .mdb. If the hackers are interested in the documents on a compromised computer, they exfiltrate them within 30-50 minutes.
Gamaredon employs a clever technique of planting up to 120 infected files per week on compromised systems to increase the chances of re-infection. Even after disinfection attempts, any remaining infected files could lead to renewed infection, especially if users reinstall the OS without checking the documents. Additionally, inserting USB sticks into an infected computer's ports can lead to further infection of isolated networks through Gamaredon's payloads.
Gamaredon, is Russian state-sponsored hacking group, poses a significant cyber-espionage threat to Ukraine, executing rapid attacks and stealing data within an hour. Employing various techniques like email-based infection and malware dissemination, they target critical organizations.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]