logo

Gamaredon_Group__2020__Gamaredon_APT_Group_Use_Covid-19_Lure_in_Campaigns_-_TrendLabs_Security_Intelligence_Blog.pdf

ID: ecd458db-7d14-43f2-9165-be8e51da0891

STIX ID: report--ecd458db-7d14-43f2-9165-be8e51da0891

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2020-04-27

Last Modified Date: 2020-04-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro observed the Gamaredon APT using COVID-19-themed spearphishing emails that delivered DOCX template injections and malicious macros which drop obfuscated VBS; the VBS downloads, XOR-decrypts and executes additional payloads, registers persistence via Run keys, and contacts C2 servers. The report includes code samples, file and domain/IP IoCs, MITRE ATT&CK mappings, and recommended mitigations.