Technical report Armagedon.pdf
ID: acc9cf7a-2180-4453-84e1-33d936fdfac1
STIX ID: report--acc9cf7a-2180-4453-84e1-33d936fdfac1
Threat Score
88/100
Uploaded: 2026-08-11
Published Date: 2021-11-03
Last Modified Date: 2021-11-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** The Security Service of Ukraine details Gamaredon/Armageddon, an FSB-affiliated APT active since 2013–2014 that targets Ukrainian government and defense bodies using large-scale spearphishing, malicious Office templates/macros, PowerShell/VBS droppers and the Pterodo/Pteranodon malware family to gain persistence, harvest documents and credentials, propagate via removable media, and exfiltrate data to dynamic C2 infrastructure; the report enumerates TTPs, exploited vulnerabilities (CVE-2018-20250, CVE-2017-0199), observed artifacts and concrete mitigations.
