Russische Gamaredon-Hacker zielen mit Info-Stealing-Malware auf ukrainische Regierung

Teilen:

An ongoing espionage campaign operated by the Russia-linked Gamaredon group is targeting employees of Ukrainian government, defense, and law enforcement agencies with a piece of custom-made information stealing malware.

“The adversary is using phishing documents containing lures related to the Russian invasion of Ukraine,” Cisco Talos researchers Asheer Malhotra and Guilherme Venere sagte in a technical write-up shared with The Hacker News. “LNK files, PowerShell, and VBScript enable initial access, while malicious binaries are deployed in the post-infection phase.”

Active since 2013, Gamaredon – also known as Actinium, Armageddon, Primitive Bear, Shuckworm, and Trident Ursa – has been linked to numerous attacks aimed at Ukrainian entities in the aftermath of Russia’s military invasion of Ukraine in late February 2022.

The targeted phishing operation, observed as recently as August 2022, also follows similar intrusions uncovered by Symantec last month involving the use of malware such as Giddome and Pterodo. The primary goal of these attacks is to establish long-term access for espionage and data theft.

It entails leveraging decoy Einkaufsmodus Microsoft Word documents containing lures pertaining to the Russo-Ukrainian war that are distributed via email messages to infect targets. When opened, macros concealed within remote templates are executed to retrieve RAR containing LNK files.

Infection Chain

The LNK files seemingly reference intelligence briefings related to the Russian invasion of Ukraine to trick unsuspecting victims into opening the shortcuts, resulting in the execution of a PowerShell beacon script that ultimately paves the way for next-stage payloads.

This includes another PowerShell script that’s used to provide persistent access to compromised system and deliver additional malware, including a new malware capable of plundering files (.doc, .docx, .xls, .rtf, .odt, .txt, .jpg, .jpeg, .pdf, .ps1, .rar, .zip, .7z, and .mdb) from the machine as well as any removable drive connected to it.

“The infostealer is a dual-purpose malware that includes capabilities for exfiltrating specific file types and deploying additional binary and script-based payloads on an infected endpoint,” the researchers said, adding it may be a component of the Giddome backdoor family.

The findings come at a time cyberattacks continue to be an important part of modern hybrid war strategy amidst the conflict between Russia and Ukraine. Earlier this month, shoppingmode Google‘s Threat Analysis Group (TAG) disclosed as many as five different campaigns mounted by a group with links to the Conti cybercrime cartel.

 

https://thehackernews.com/2022/09/russian-gamaredon-hackers-target.html?

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
16.57 Uhr, Juni 1, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
broken clouds
Luftfeuchtigkeit: 48 %
Druck: 1013 mb
Wind: 12 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 58%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0 mm 0% 12 mph 64 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 11 mph 84 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 16 mph 93 % 1014 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
10° | 20°°C 0 mm 0% 13 mph 80 % 1010 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 13 mph 95 % 1008 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 12 mph 50 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 8 mph 64 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 84 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 79 % 1016 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 51 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 35 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 7 mph 30 % 1017 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,307.25
0.12%
Ethereum(ETH)
€2,219.54
-0.85%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.89
-1.10%
Solana(SOL)
€135.75
-1.12%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.169124
-0.46%
Shiba Inu(SHIB)
€0.000011
2.28%
Pepe(PEPE)
€0.000011
0.18%
Peanut das Eichhörnchen(PNUT)
€0.231219
2.82%
Nach oben scrollen