ATT&CKGroupsGamaredon Group

Gamaredon Group

G0047

Threat group.View on attack.mitre.org

About this group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.

Techniques used70

Procedure examples70

TechniqueProcedure example
T1001
Data Obfuscation

Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings.

T1005
Data from Local System

Gamaredon Group has collected files from infected systems and uploaded them to a C2 server.

T1012
Query Registry

Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses.

T1016.001
Internet Connection Discovery

Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status.

T1020
Automated Exfiltration

Gamaredon Group has used modules that automatically upload gathered documents to the C2 server.

T1021.005
VNC

Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.

T1025
Data from Removable Media

A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives.

T1027
Obfuscated Files or Information

Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file.

T1027.004
Compile After Delivery

Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in Microsoft.CSharp.CSharpCodeProvider class.

T1027.010
Command Obfuscation

Gamaredon Group has used obfuscated or encrypted scripts.

T1027.012
LNK Icon Smuggling

Gamaredon Group has used LNK files to hide malicious scripts for execution.

T1027.015
Compression

Gamaredon Group has delivered malicious payloads within compressed archives and zip files.

T1027.016
Junk Code Insertion

Gamaredon Group has obfuscated .NET executables by inserting junk code.

T1033
System Owner/User Discovery

A Gamaredon Group file stealer can gather the victim's username to send to a C2 server.

T1036.005
Match Legitimate Resource Name or Location

Gamaredon Group has used legitimate process names to hide malware including svchosst. Additionally, Gamaredon Group disguised malicious ZIP archives as Office documents that are related to the invasion.

View all 70 procedure examples

Software6

Campaigns0

None recorded.

References6

  1. Bleepingcomputer Gamardeon FSB November 2021 Open source
    Toulas, B. (2018, November 4). Ukraine links members of Gamaredon hacker group to Russian FSB. Retrieved April 15, 2022.
  2. ESET Gamaredon June 2020 Open source
    Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.
  3. Microsoft Actinium February 2022 Open source
    Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.
  4. Palo Alto Gamaredon Feb 2017 Open source
    Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.
  5. Symantec Shuckworm January 2022 Open source
    Symantec. (2022, January 31). Shuckworm Continues Cyber-Espionage Attacks Against Ukraine. Retrieved February 17, 2022.
  6. TrendMicro Gamaredon April 2020 Open source
    Kakara, H., Maruyama, E. (2020, April 17). Gamaredon APT Group Use Covid-19 Lure in Campaigns. Retrieved May 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.