Threat Advisory

New Report Reveals Shuckworm's Long-Running Intrusions on Ukrainian Organizations

Threat: Malware
Threat Actor Name: Shuckworm
Threat Actor Type: State-Sponsored
Targeted Region: Ukraine
Alias: Gamaredon Group, G0047, Primitive Bear, Temp.Armageddon/UNC530, DEV-0157/Actinum/Aqua Blizzard, Dancing Salome, Trident Ursa, BlueAlpha, Iron Tilden, UAC-0010, Blue Otso, APT-C-53 , Winterflounder/Armageddon/SectorC08/Callisto
Threat Actor Region: Russia
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]
 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

The attacks which started in 2023, targeted security services, military, and government organizations. According to researchers the Russian group has successfully carried out long-running intrusions, lasting up to three months, and aimed to steal sensitive information. Shuckworm, also known by various names like Aqua Blizzard, Armageddon, Gamaredon, Iron Tilden, Primitive Bear, Trident Ursa, UNC530, and Winterflounder, has been active since at least 2013. The cyber espionage activities involve spear-phishing campaigns that trick victims into opening malicious attachments, leading to the deployment of information stealers such as Giddome, Pterodo, GammaLoad, and GammaSteel on compromised systems.

Shuckworm's infrastructure can be identified through the use of specific Dynamic DNS providers, Russian hosting providers, and remote template injection techniques. In the latest attacks, the threat actor has been observed using a new PowerShell script to propagate the Pterodo backdoor through USB drives. Additionally, Shuckworm has expanded its use of Telegram channels to retrieve IP addresses of servers hosting the payloads and has stored command-and-control (C2) addresses on Telegraph, a blogging platform owned by Telegram. Shuckworm managed to breach the machines of human resources departments in the targeted organizations, indicating an attempt to gather information about individuals working in those entities. These findings highlight Shuckworm's reliance on short-lived infrastructure and its continuous evolution of tactics and tools to evade detection.

The Russian threat actor Shuckworm, on Ukrainian entities, targeting security services, military, and government organizations. The group spear-phishing campaigns and information stealers to gain unauthorized access and steal sensitive information. Recent findings highlight the threat actor's use of new techniques, including PowerShell scripts and Telegram channels, while emphasizing their persistent focus on Ukraine and the evolving nature of their tactics.

 

Threat Profile:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1053 Scheduled Task/Job
T1059 Command and Scripting Interpreter
Defense Evasion T1036 Masquerading
Credential Access T1555 Credentials from Password Stores
Discovery T1135 Network Share Discovery
Lateral Movement T1570 Lateral Tool Transfer
Collection T1005 Data from Local System
Command and Control T1105 Ingress Tool Transfer
Exfiltration T1041 Exfiltration Over C2 Channel

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/new-report-reveals-shuckworms-long.html

[/emaillocker]
crossmenu