The Russia-linked Gamaredon APT group tried to compromise an unnamed Western government entity operating in Ukraine while geopolitical tensions between Russia and Ukraine have escalated dramatically.
Palo Alto Network researchers mapped out three large clusters of the infrastructure used by the nation-state APT group used to support different phishing and malware campaigns. These clusters link to over 700 malicious domains, 215 IP addresses, and over 100 samples of malware.
The threat actor, also known as Shuckworm, Armageddon, or Primitive Bear, has focused its offensive cyber-attacks against Ukrainian government officials and organizations since 2013.
Unlike most threat actors that discard domains after their use in a cyber-attack, Gamaredon recycles their domains by consistently rotating them across new infrastructure.
The phishing attack leveraged a job search and employment platform in Ukraine where attackers uploaded their malware downloader in the form of a resume for an active job listing related to the targeted organization.
The investigation into the activity of the Gamaredon APT revealed that the cyberspies carried out a campaign against the State Migration Service of Ukraine in early December.
The state-sponsored hackers used weaponized Word docs as a lure to deliver the open-source UltraVNC virtual network computing (VNC) software for maintaining remote access to infected computers.
In November, Ukraine’s premier law enforcement and counterintelligence disclosed the real identities of five alleged members of the Russia-linked APT group Gamaredon that are suspected to be components of the Russian Federal Security Service (FSB).
According to the Security Service of Ukraine (SSU) Cyber Security Department, the group carried out over 5,000 cyberattacks against public authorities and critical infrastructure of Ukraine.
Image Credits : Anomali














Comments