216.73.217.22

Gamaredon campaign abuses LNK files to distribute Remcos backdoor

· Published 28/03/2025 15:56 · Modified 31/03/2025 11:26

Export JSON

Essential information

Published
28/03/2025 15:56
Modified
31/03/2025 11:26
Tags
2025-03-28 dll sideloading gthost hyperhosting lnk files phishing powershell remcos ukraine
Related entities
1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 5 others

Description

A campaign targeting users in with malicious has been observed since November 2024. The files, using Russian words related to troop movements as lures, run a downloader contacting geo-fenced servers in Russia and Germany. The second stage payload uses DLL side loading to execute the backdoor. The activity is attributed to the Gamaredon threat actor group with medium confidence. The campaign uses the invasion of as a theme in attempts, distributing disguised as Office documents. The servers used are mostly hosted by and ISPs. The attack chain involves to load the backdoor, which communicates with a C2 server on a specific port.

External references