Gamaredon_Group__2020__Gamaredon_group_grows_its_game_WeLiveSecurity.pdf
ID: 09bf3eba-9e64-49b9-90e7-a9ed53ee7694
STIX ID: report--09bf3eba-9e64-49b9-90e7-a9ed53ee7694
Threat Score
80/100
Uploaded: 2026-08-15
Published Date: 2020-08-24
Last Modified Date: 2020-08-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This ESET analysis details the Gamaredon APT’s active spearphishing campaigns and post-compromise toolset: an Outlook VBA module that abuses compromised mailboxes to send malicious attachments, Office macro and remote-template injection modules for lateral movement and persistence, multiple downloader variants (including an on-host C# compiler and GitHub-hosted payload retrieval), and file-stealer/backdoor implants that enumerate and exfiltrate Office documents; the report also lists IoCs, C2 domain patterns and mapped MITRE ATT&CK techniques.
