Gamaredon_Group__2022__CiscoTalos_GamaredonAPT-targets-Ukrainian-new-campaign_09-15-2022.pdf
ID: d2e055b4-3146-4a52-a57c-8ee167b999b6
STIX ID: report--d2e055b4-3146-4a52-a57c-8ee167b999b6
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2023-03-03
Last Modified Date: 2023-03-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Gamaredon APT is running a targeted espionage campaign against Ukrainian government and affiliated organizations using spear-phishing Office documents that lead to LNK-triggered mshta execution and modular PowerShell/VBScript payloads; attackers deploy a custom information stealer that exfiltrates sensitive files, supports follow-on payload delivery, and uses multiple C2 domains/IPs and persistence mechanisms — the report includes detailed technical analysis, IOCs, and mitigation guidance.
