Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupGamaredon Group | Gamaredon Group has collected files from infected systems and uploaded them to a C2 server. |
| T1025 Data from Removable Media |
GroupGamaredon Group | A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives. |
| T1027.010 Command Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated or encrypted scripts. |
| T1039 Data from Network Shared Drive |
GroupGamaredon Group | Gamaredon Group malware has collected Microsoft Office documents from mapped network drives. |
| T1041 Exfiltration Over C2 Channel |
GroupGamaredon Group | A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server. |
| T1047 Windows Management Instrumentation |
GroupGamaredon Group | Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`. |
| T1059.001 PowerShell |
GroupGamaredon Group | Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload. |
| T1059.005 Visual Basic |
GroupGamaredon Group | Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe. |
| T1070.004 File Deletion |
GroupGamaredon Group | Gamaredon Group tools can delete files used during an operation. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server. |
| T1083 File and Directory Discovery |
GroupGamaredon Group | Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host. |
| T1090 Proxy |
GroupGamaredon Group | Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic. |
| T1102.002 Bidirectional Communication |
GroupGamaredon Group | Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1106 Native API |
GroupGamaredon Group | Gamaredon Group malware has used |
| T1112 Modify Registry |
GroupGamaredon Group | Gamaredon Group has removed security settings for VBA macro execution by changing registry values |
| T1113 Screen Capture |
GroupGamaredon Group | Gamaredon Group's malware can take screenshots of the compromised computer every minute. |
| T1120 Peripheral Device Discovery |
GroupGamaredon Group | Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives. |
| T1140 Deobfuscate/Decode Files or Information |
GroupGamaredon Group | Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications. |
| T1204.001 Malicious Link |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on a link pointing to a malicious HTML file leading to follow-on malicious content. |
| T1218.005 Mshta |
GroupGamaredon Group | Gamaredon Group has used `mshta.exe` to execute malicious files. |
| T1221 Template Injection |
GroupGamaredon Group | Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupGamaredon Group | Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence. |
| T1559.001 Component Object Model |
GroupGamaredon Group | Gamaredon Group malware can insert malicious macros into documents using a |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1568.001 Fast Flux DNS |
GroupGamaredon Group | Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method. |
| T1583.001 Domains |
GroupGamaredon Group | Gamaredon Group has registered multiple domains to facilitate payload staging and C2. |
| T1583.003 Virtual Private Server |
GroupGamaredon Group | Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia. |
| T1588.002 Tool |
GroupGamaredon Group | Gamaredon Group has used various legitimate tools, such as `mshta.exe` and Reg, and services during operations. |
| T1685 Disable or Modify Tools |
GroupGamaredon Group | Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.