GamaCopy mimics the Russian Gamaredon APT and launches attacks against Russian-speaking targets

0 19
GamaCopy mimics the Russian Gamaredon APT and launches attacks against Russi...

GamaCopy mimics the Russian Gamaredon APT and launches attacks against Russian-speaking targets

Recently, the Knownsec 404 Advanced Threat Intelligence Team analyzed an attack campaign targeting Russian-speaking targets. The attackers used military-themed lure documents, 7z self-extracting files (SFX) as payloads, and utilized UltraVNC for remote control, mimicking the tactics, techniques, and procedures (TTPs) of the Russian Gamaredon APT organization. Researchers linked this activity to the APT organization Core Werewolf (also known as Awaken Likho, PseudoGamaredon) because it mimicked Gamaredon, and therefore named it GamaCopy.

GamaCopy mimics the Russian Gamaredon APT and launches attacks against Russian-speaking targets

GamaCopy has been active since August 2021 and was discovered in June 2023. The organization mainly targets Russia's defense and infrastructure sectors, mimicking Gamaredon's TTPs.

The Knownsec 404 Advanced Threat Intelligence team pointed out in the report: "By tracing the source of the samples, we associate them with the Core Werewolf organization, which has repeatedly attacked Russia. It is well known that there is another interesting pair of APT attack organizations in South Asia, namely SideWinder and SideCopy, which have an intertwined relationship. The discovered attack activity imitates the Gamaredon organization targeting Ukraine, therefore, it can be named GamaCopy."

GamaCopy's attack methods and characteristics

Researchers noted that other security vendors had previously attributed multiple similar historical samples to the Gamaredon organization. GamaCopy deceived some security vendors that did not conduct in-depth analysis through successful false flag operations.

The attack chain starts with a 7-Zip self-extracting (SFX) file that releases the payload, including a batch script to install UltraVNC and display the lure PDF. The attacker renamed the UltraVNC executable file to "OneDrivers.exe" in an attempt to mimic Microsoft's OneDrive binary file to evade detection.

The lure documents used in the GamaCopy attacks mainly revolve around military facilities, reflecting the theme of the Russia-Ukraine conflict. However, unlike Gamaredon's use of Ukrainian language lures, GamaCopy targets Russian users.

image

Researchers' assessment of GamaCopy

The report concludes: "From the perspective of code similarity, language use in lure documents, and port assets, it is more inclined to attribute the discovered attack samples to the GamaCopy organization. Since its exposure, this organization has frequently mimicked the TTPs of the Gamaredon organization and cleverly used open-source tools as cover, confusing the public while achieving its own goals."

The Knownsec 404 team also released intrusion indicators (IoCs) for this attack activity.

Reference source:

GamaCopy targets Russia mimicking Russia-linked Gamaredon APT

你可能想看:

Git leak && AWS AKSK && AWS Lambda cli && Function Information Leakage && JWT secret leak

4.5 Main person in charge reviews the simulation results, sorts out the separated simulation issues, and allows the red and blue teams to improve as soon as possible. The main issues are as follows

Distributed Storage Technology (Part 2): Analysis of the architecture, principles, characteristics, and advantages and disadvantages of wide-column storage and full-text search engines

As announced today, Glupteba is a multi-component botnet targeting Windows computers. Google has taken action to disrupt the operation of Glupteba, and we believe this action will have a significant i

b) It should have a login failure handling function, and should configure and enable measures such as ending the session, limiting the number of illegal login attempts, and automatically logging out w

5. Collect exercise results The main person in charge reviews the exercise results, sorts out the separated exercise issues, and allows the red and blue sides to improve as soon as possible. The main

Fake Google ads target Microsoft ad accounts, and malware attacks are upgraded again

Data security can be said to be a hot topic in recent years, especially with the rapid development of information security technologies such as big data and artificial intelligence, the situation of d

Bubba AI launches open-source compliance platform Comp AI, helping 100,000 startups achieve security compliance

Emergency response of the Windows system from the perspective of permission maintenance

最后修改时间:
admin
上一篇 2025年03月29日 07:27
下一篇 2025年03月29日 07:50

评论已关闭