SaintBear__2023__Symantec_Graphiron-Russian-Malware-Deployed-Against-Ukraine_02-08-2023.pdf
ID: 74af5ab0-3191-4d7e-ae53-f366b935df44
STIX ID: report--74af5ab0-3191-4d7e-ae53-f366b935df44
Threat Score
68/100
Uploaded: 2026-08-19
Published Date: 2023-03-03
Last Modified Date: 2023-03-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Nodaria group has deployed Graphiron, a Go-based information-stealing malware with a downloader and payload, designed to harvest system information, credentials, screenshots, and files from infected machines in Ukraine. The campaign uses AES-encrypted C2 communications and hardcoded downloader behavior, with associated IOCs including SHA-256 hashes and a known C2 address, and traces the tool's lineage to prior Nodaria malware, suggesting an ongoing threat actor campaign against Ukrainian targets.
