ATT&CKReferencesCERT-EE Gamaredon January 2021

CERT-EE Gamaredon January 2021

CERT-EE. (2021, January 27). Gamaredon Infection: From Dropper to Entry. Retrieved February 17, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
GroupGamaredon Group

Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`.

T1053.005
Scheduled Task
GroupGamaredon Group

Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed.

T1059.003
Windows Command Shell
GroupGamaredon Group

Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file.

T1059.005
Visual Basic
GroupGamaredon Group

Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe.

T1070.004
File Deletion
GroupGamaredon Group

Gamaredon Group tools can delete files used during an operation.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1082
System Information Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server.

T1112
Modify Registry
GroupGamaredon Group

Gamaredon Group has removed security settings for VBA macro execution by changing registry values HKCU\Software\Microsoft\Office\<version>\<product>\Security\VBAWarnings and HKCU\Software\Microsoft\Office\<version>\<product>\Security\AccessVBOM. Gamaredon Group has also modified Registry keys to hide folders and system files and to add the C2 address under `HKEY_CURRENT_USER\Console\WindowsUpdate`.

T1204.002
Malicious File
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files.

T1221
Template Injection
GroupGamaredon Group

Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems.

T1491.001
Internal Defacement
GroupGamaredon Group

Gamaredon Group has left taunting images and messages on the victims' desktops as proof of system access.

T1547.001
Registry Run Keys / Startup Folder
GroupGamaredon Group

Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence.

T1561.001
Disk Content Wipe
GroupGamaredon Group

Gamaredon Group has used tools to delete files and folders from victims' desktops and profiles.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.