logo

Gamaredon_Group__2022__CiscoTalos_GamaredonAPT-targets-Ukrainian-new-campaign_09-15-2022.pdf

ID: d2e055b4-3146-4a52-a57c-8ee167b999b6

STIX ID: report--d2e055b4-3146-4a52-a57c-8ee167b999b6

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2023-03-03

Last Modified Date: 2023-03-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Gamaredon APT is running a targeted espionage campaign against Ukrainian government and affiliated organizations using spear-phishing Office documents that lead to LNK-triggered mshta execution and modular PowerShell/VBScript payloads; attackers deploy a custom information stealer that exfiltrates sensitive files, supports follow-on payload delivery, and uses multiple C2 domains/IPs and persistence mechanisms — the report includes detailed technical analysis, IOCs, and mitigation guidance.