Gamaredon_Group__2020__Cyberwarfare_A_deep_dive_into_the_latest_Gamaredon_Espionage_Campaign.pdf
ID: 48cd0015-7c2d-4d5e-8295-b3edb0af9382
STIX ID: report--48cd0015-7c2d-4d5e-8295-b3edb0af9382
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2020-02-24
Last Modified Date: 2020-02-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Cybaze-Yoroi ZLab blog post provides a technical deep-dive into the Gamaredon (Pteranodon) espionage campaign targeting Ukrainian entities: it documents the spear-phishing Office document with template injection, subsequent .dot and VBS stages, SFX-packed payloads, a .NET component, persistence mechanisms (Startup VBS and scheduled tasks), C2 infrastructure (masseffect.space and ddns domains), YARA detection rules and multiple hashes/IOCs for detection and response.
