Gamaredon_Group__2020__Gamaredon_APT_Group_Use_Covid-19_Lure_in_Campaigns_-_TrendLabs_Security_Intelligence_Blog.pdf
ID: ecd458db-7d14-43f2-9165-be8e51da0891
STIX ID: report--ecd458db-7d14-43f2-9165-be8e51da0891
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2020-04-27
Last Modified Date: 2020-04-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro observed the Gamaredon APT using COVID-19-themed spearphishing emails that delivered DOCX template injections and malicious macros which drop obfuscated VBS; the VBS downloads, XOR-decrypts and executes additional payloads, registers persistence via Run keys, and contacts C2 servers. The report includes code samples, file and domain/IP IoCs, MITRE ATT&CK mappings, and recommended mitigations.
