logo

Gamaredon_Group__2020__Cyberwarfare_A_deep_dive_into_the_latest_Gamaredon_Espionage_Campaign.pdf

ID: 48cd0015-7c2d-4d5e-8295-b3edb0af9382

STIX ID: report--48cd0015-7c2d-4d5e-8295-b3edb0af9382

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2020-02-24

Last Modified Date: 2020-02-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Cybaze-Yoroi ZLab blog post provides a technical deep-dive into the Gamaredon (Pteranodon) espionage campaign targeting Ukrainian entities: it documents the spear-phishing Office document with template injection, subsequent .dot and VBS stages, SFX-packed payloads, a .NET component, persistence mechanisms (Startup VBS and scheduled tasks), C2 infrastructure (masseffect.space and ddns domains), YARA detection rules and multiple hashes/IOCs for detection and response.