ATT&CKReferencesVenereCiscoTalos_Gamaredon_Mar2025

VenereCiscoTalos_Gamaredon_Mar2025

Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027.012
LNK Icon Smuggling
GroupGamaredon Group

Gamaredon Group has used LNK files to hide malicious scripts for execution.

T1027.015
Compression
GroupGamaredon Group

Gamaredon Group has delivered malicious payloads within compressed archives and zip files.

T1036.005
Match Legitimate Resource Name or Location
GroupGamaredon Group

Gamaredon Group has used legitimate process names to hide malware including svchosst. Additionally, Gamaredon Group disguised malicious ZIP archives as Office documents that are related to the invasion.

T1055
Process Injection
GroupGamaredon Group

Gamaredon Group has injected Remcos into explorer.exe.

T1059.001
PowerShell
GroupGamaredon Group

Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1105
Ingress Tool Transfer
GroupGamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.

T1204.002
Malicious File
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files.

T1480
Execution Guardrails
GroupGamaredon Group

Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations.

T1564.003
Hidden Window
GroupGamaredon Group

Gamaredon Group has used hidcon to run batch files in a hidden console window. Gamaredon Group has also executed PowerShell in a hidden window.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

T1571
Non-Standard Port
GroupGamaredon Group

Gamaredon Group has used port 6856 for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.