news.mlab.sh
Threat intelligence
Threat actor

Gamaredon Group

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Russia
Targeted countries
Russia
TLP
WHITE

(Lookingglass) The Lookingglass Cyber Threat Intelligence Group (CTIG) has been tracking an ongoing cyber espionage campaign named “Operation Armageddon”. The name was derived from multiple Microsoft Word documents used in the attacks. “Armagedon” (spelled incorrectly) was found in the “Last Saved By” and “Author” fields in multiple Microsoft Word documents. Although continuously developed, the campaign has been intermittently active at a small scale, and uses unsophisticated techniques. The attack timing suggests the campaign initially started due to Ukraine’s decision to accept the Ukraine-­‐European Union Association Agreement (AA). The agreement was designed to improve economic integrations between Ukraine and the European Union. Russian leaders publicly stated that they believed this move by Ukraine directly threatened Russia’s national security. Although initial steps to join the Association occurred in March 2012, the campaign didn’t start until much later (mid‐2013), as Ukraine and the EU started to more actively move towards the agreement. Russian actors began preparing for attacks in case Ukraine finalized the AA. The earliest identified modification timestamp of malware used in this campaign is June 26, 2013. A group of files with modification timestamps between August 12 and September 16, 2013 were used in the first wave of spear-phishing attacks, targeting government officials prior to the 10th Yalta Annual Meeting: “Changing Ukraine in a Changing World: Factors of Success.”

Also known as

ActiniumAqua BlizzardArmageddonBlue OtsoBlueAlphaCallistoDEV-0157G0047Gamaredon GroupIron TildenNastyShrewPrimitive BearSectorC08ShuckwormTrident UrsaUAC-0010UNC530Winterflounder

Tooling and malware

PowerPunchPteranodonQuietSievePingRegRemcos

MITRE ATT&CK techniques

T1005 Data from Local SystemT1025 Data from Removable MediaT1039 Data from Network Shared DriveT1113 Screen CaptureT1119 Automated CollectionT1001 Data ObfuscationT1090 ProxyT1095 Non-Application Layer ProtocolT1102 Web ServiceT1105 Ingress Tool TransferT1568 Dynamic ResolutionT1571 Non-Standard PortT1112 Modify RegistryT1685 Disable or Modify ToolsT1012 Query RegistryT1033 System Owner/User DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1120 Peripheral Device DiscoveryT1047 Windows Management InstrumentationT1106 Native APIT1020 Automated ExfiltrationT1041 Exfiltration Over C2 ChannelT1080 Taint Shared ContentT1091 Replication Through Removable MediaT1534 Internal SpearphishingT1137 Office Application StartupT1027 Obfuscated Files or InformationT1055 Process InjectionT1140 Deobfuscate/Decode Files or InformationT1221 Template InjectionT1480 Execution GuardrailsT1620 Reflective Code Loading

Coverage 4