Operation-Groundbait.pdf
ID: ab837326-f388-4dc9-9e29-064bb55d8628
STIX ID: report--ab837326-f388-4dc9-9e29-064bb55d8628
Threat Score
75/100
Uploaded: 2026-08-11
Published Date: 2016-05-18
Last Modified Date: 2016-05-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary
ESET's "Operation Groundbait" report documents the Prikormka modular surveillance malware used in targeted spear-phishing campaigns primarily against individuals in Ukraine (notably separatists and select high-value targets). The analysis describes the dropper, persistence via DLL load-order hijacking, a downloader/core architecture, multiple data-stealing modules (keystroke logging, screenshots, microphone, Skype, document exfiltration, saved passwords, geolocation), C2 infrastructure and extensive IoCs (domains, IPs, mutexes, SHA-1s), and provides campaign identifiers and attribution indicators pointing to operators likely working from within Ukraine.
