logo

Gamaredon_Group__2020__Gamaredon_group_grows_its_game_WeLiveSecurity.pdf

ID: 09bf3eba-9e64-49b9-90e7-a9ed53ee7694

STIX ID: report--09bf3eba-9e64-49b9-90e7-a9ed53ee7694

Threat Score

80/100

Uploaded: 2026-08-15

Published Date: 2020-08-24

Last Modified Date: 2020-08-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This ESET analysis details the Gamaredon APT’s active spearphishing campaigns and post-compromise toolset: an Outlook VBA module that abuses compromised mailboxes to send malicious attachments, Office macro and remote-template injection modules for lateral movement and persistence, multiple downloader variants (including an on-host C# compiler and GitHub-hosted payload retrieval), and file-stealer/backdoor implants that enumerate and exfiltrate Office documents; the report also lists IoCs, C2 domain patterns and mapped MITRE ATT&CK techniques.