logo

Gamaredon_Group__2022__Symantec-Shuckworm-Espionage-Group-Campaign-Against-Ukraine_04-20-2022.pdf

ID: b65d1b4d-8f42-4641-9d8a-69a0fcbacf50

STIX ID: report--b65d1b4d-8f42-4641-9d8a-69a0fcbacf50

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2022-04-29

Last Modified Date: 2022-04-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Russian-linked Shuckworm espionage group continues an intense, persistent campaign against Ukrainian organizations using multiple variants of the Backdoor.Pterodo VBS droppers (variants B, C, D, E), scheduled-task persistence, API hammering, PowerShell fetch-and-execute stages, and additional tools like UltraVNC and Process Explorer; the analysis includes malware behavior, C2 domains and IOCs, and mitigation guidance.