logo

Operation-Groundbait.pdf

ID: ab837326-f388-4dc9-9e29-064bb55d8628

STIX ID: report--ab837326-f388-4dc9-9e29-064bb55d8628

Threat Score

75/100

Uploaded: 2026-08-11

Published Date: 2016-05-18

Last Modified Date: 2016-05-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary ESET's "Operation Groundbait" report documents the Prikormka modular surveillance malware used in targeted spear-phishing campaigns primarily against individuals in Ukraine (notably separatists and select high-value targets). The analysis describes the dropper, persistence via DLL load-order hijacking, a downloader/core architecture, multiple data-stealing modules (keystroke logging, screenshots, microphone, Skype, document exfiltration, saved passwords, geolocation), C2 infrastructure and extensive IoCs (domains, IPs, mutexes, SHA-1s), and provides campaign identifiers and attribution indicators pointing to operators likely working from within Ukraine.