ET-3346
📛 Threat Title
SIG: ET TROJAN Gamaredon.APT GammaLoad Stage 1 User-Agent Structure
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- SIG: ET TROJAN Gamaredon.APT GammaLoad Stage 1 User-Agent Structure Emerging Threats Community
Remediations (10)
-
web:attack.mitre.org
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013.
-
web:blog.sekoia.io
In part 2 of our FSB Matryoshka series, we analyze Gamaredon's Gammaload malware variant, dissecting its technical updates and deployment mechanisms.
-
web:community.emergingthreats.net
See reference for details. One note. on the sig it doesn't appear to be showing the wildcard matching before and after the PCRE so that may need to be added (the asterisk) but we need to match the previous and ending of the fake user agent too.
-
web:cybernoz.com
Gamaredon Uses GammaDrop and GammaLoad Downloaders in Multi- Stage Phishing Attacks. A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government entities using multi- stage phishing attacks and evolving malware loaders. Gamaredon, also known as UAC-0010 or Shuckworm, continues to exploit CVE-2025-8088, a directory traversal vulnerability ...
-
web:cyberpress.org
Now, Gamaredon is actively leveraging the flaw to silently compromise systems using multi- stage VBScript downloaders, specifically identifying their customized malware as GammaDrop and GammaLoad variants. Gamaredon Deploys Malware Downloaders The threat actors rely heavily on hijacked government email accounts to mask their malicious activity.
-
web:cybersecuritytimes.com
Gamaredon Deploys GammaDrop in Phishing Attacks The attack begins with spearphishing emails sent from compromised government accounts in one documented case, from a local official in Odesa Oblast carrying a malicious RAR archive.
-
web:gbhackers.com
Gamaredon Uses GammaDrop and GammaLoad Downloaders in Multi- Stage Phishing Attacks. A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government entities using multi- stage phishing attacks and evolving malware loaders.
-
web:harfanglab.io
In the absence of public analysis of these malware, this report documents Gamaredon's GammaDrop and GammaLoad downloader variants, the infrastructure behind them, and the methods used to deliver the spearphishing emails.
-
web:socprime.com
Summary The report outlines a Gamaredon campaign that abuses CVE-2025-8088 to deliver VBScript payloads through weaponized RAR archives attached to spearphishing emails aimed at Ukrainian state organizations. Once opened, the malicious archive drops a GammaDrop downloader, which retrieves a GammaLoad HTA beacon responsible for persistence and communication with Cloudflare-proxied command-and ...
-
web:www.planetjon.net
These techniques are indicative of Gamaredon's use of automated malware generation engines designed to frustrate signature-based detection systems. Once executed, GammaDrop performs its primary function: retrieving the second- stage payload, GammaLoad .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.