Gamaredon_Group__2022__Symantec-Shuckworm-Espionage-Group-Campaign-Against-Ukraine_04-20-2022.pdf
ID: b65d1b4d-8f42-4641-9d8a-69a0fcbacf50
STIX ID: report--b65d1b4d-8f42-4641-9d8a-69a0fcbacf50
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2022-04-29
Last Modified Date: 2022-04-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Russian-linked Shuckworm espionage group continues an intense, persistent campaign against Ukrainian organizations using multiple variants of the Backdoor.Pterodo VBS droppers (variants B, C, D, E), scheduled-task persistence, API hammering, PowerShell fetch-and-execute stages, and additional tools like UltraVNC and Process Explorer; the analysis includes malware behavior, C2 domains and IOCs, and mitigation guidance.
