Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.012 LNK Icon Smuggling |
GroupGamaredon Group | Gamaredon Group has used LNK files to hide malicious scripts for execution. |
| T1027.015 Compression |
GroupGamaredon Group | Gamaredon Group has delivered malicious payloads within compressed archives and zip files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupGamaredon Group | Gamaredon Group has used legitimate process names to hide malware including |
| T1055 Process Injection |
GroupGamaredon Group | Gamaredon Group has injected Remcos into explorer.exe. |
| T1059.001 PowerShell |
GroupGamaredon Group | Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1204.002 Malicious File |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files. |
| T1480 Execution Guardrails |
GroupGamaredon Group | Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations. |
| T1564.003 Hidden Window |
GroupGamaredon Group | Gamaredon Group has used |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1571 Non-Standard Port |
GroupGamaredon Group | Gamaredon Group has used port 6856 for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.