mastodon.ie is one of the many independent Mastodon servers you can use to participate in the fediverse.
Irish Mastodon - run from Ireland, we welcome all who respect the community rules and members.

Administered by:

Server stats:

1.8K
active users

#gamaredon

3 posts3 participants0 posts today

#Gamaredon : The Turncoat #Spies Relentlessly #Hacking #Ukraine

For the past decade, this group of #FSB #hackers—including “traitor” #Ukrainian intelligence officers—has used a grinding barrage of #intrusion campaigns to make life hell for their former countrymen and #cybersecurity defenders.
#security #privacy

wired.com/story/gamaredon-turn

WIRED · Gamaredon: The Turncoat Spies Relentlessly Hacking UkraineBy Andy Greenberg

Gamaredon Targets Troops via Malware

Pulse ID: 67eb266fe6461777fb05efa7
Pulse Link: otx.alienvault.com/pulse/67eb2
Pulse Author: cryptocti
Created: 2025-03-31 23:34:07

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

Gamaredon campaign abuses LNK files to distribute Remcos backdoor

A campaign targeting users in Ukraine with malicious LNK files has been observed since November 2024. The files, using Russian words related to troop movements as lures, run a PowerShell downloader contacting geo-fenced servers in Russia and Germany. The second stage payload uses DLL side loading to execute the Remcos backdoor. The activity is attributed to the Gamaredon threat actor group with medium confidence. The campaign uses the invasion of Ukraine as a theme in phishing attempts, distributing LNK files disguised as Office documents. The servers used are mostly hosted by GTHost and HyperHosting ISPs. The attack chain involves DLL sideloading to load the Remcos backdoor, which communicates with a C2 server on a specific port.

Pulse ID: 67e6c6b5e3b5eec595438366
Pulse Link: otx.alienvault.com/pulse/67e6c
Pulse Author: AlienVault
Created: 2025-03-28 15:56:37

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

(talosintelligence.com) Gamaredon APT Targets Ukraine with Remcos Backdoor Using War-Themed Lures blog.talosintelligence.com/gam

Cisco Talos is tracking a campaign targeting Ukrainian users with malicious LNK files that deliver the Remcos backdoor. The campaign, attributed with medium confidence to the Gamaredon APT group, uses Russian-language lures related to troop movements in Ukraine. The attack chain involves LNK files that execute PowerShell code to download a ZIP file containing the Remcos backdoor, which is then executed through DLL side-loading techniques. The attackers use geo-fenced servers in Russia and Germany that restrict access to Ukrainian IP addresses. This represents a continuation of Gamaredon's targeting of Ukrainian entities, though their use of the commercial Remcos backdoor marks a shift from their typical custom tooling.

Cisco Talos Blog · Gamaredon campaign abuses LNK files to distribute Remcos backdoorCisco Talos is actively tracking an ongoing campaign, targeting users in Ukraine with malicious LNK files which run a PowerShell downloader since at least November 2024.

Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.

A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.

#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: securityboulevard.com/2023/11/

Security Boulevard · ‘LitterDrifter’ Russian USB Worm Leaks from Ukraine War ZoneFSB APT USB VBS LNK DLL: WTH? Flash drive sharing malware escapes Україна. Gamaredon fingered as perps.