APT-C-53 (Gamaredon)
· Published 21/12/2025 08:45 · Modified 21/12/2025 08:45
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 08:45
- Modified
- 21/12/2025 08:45
- Updated at
- 21/12/2025 08:45
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 21 attack patterns (mitre), 3 sectors, 1 countries, 14 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
8 MITREs 11 Observables 1 APT
-
12 MITREs 6 Observables 1 APT
Attack patterns (MITRE) (21)
-
T1071 usesApplication Layer Protocol MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1547.001 usesRegistry Run Keys / Startup Folder MITRE
-
T1566 usesPhishing MITRE
-
T1021.001 usesRemote Desktop Protocol MITRE
-
T1059.005 usesVisual Basic MITRE
-
T1059.007 usesJavaScript MITRE
-
T1608.001 usesUpload Malware MITRE
-
T1091 usesReplication Through Removable Media MITRE
-
T1132.001 usesStandard Encoding MITRE
-
T1073 uses
-
T1064 usesScripting MITRE
Sectors (3)
-
Government targets
-
Defense targets
-
Media targets
Countries (1)
-
Ukraine targets
Indicators (14)
-
nandayo.ruindicates -
[email protected]indicates -
euw.devtunnels.msindicates -
wilderness-activists-gazette-purse.trycloudflare.comindicates -
isp-quotes-yemen-spectrum.trycloudflare.comindicates -
[email protected]indicates -
fulagam.ruindicates -
mind-apple-slightly-twiki.trycloudflare.comindicates -
b95eea2bee2113b7b5c7af2acf6c6cbde05829fab79ba86694603d4c1f33fddaindicates -
painful-pam-noise-operating.trycloudflare.comindicates -
bulam.ruindicates -
http://nandayo.ru/srgssdfsfindicates