ATT&CKReferencesSymantecCarbonBlack_ShuckwormUSB_Apr2025

SymantecCarbonBlack_ShuckwormUSB_Apr2025

Threat Hunter Team, Symantec and Carbon Black. (2025, April 10). Shuckworm Targets Foreign Military Mission Based in Ukraine. Retrieved July 23, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1012
Query Registry
GroupGamaredon Group

Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses.

T1016.001
Internet Connection Discovery
GroupGamaredon Group

Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status.

T1027
Obfuscated Files or Information
GroupGamaredon Group

Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file.

T1027.010
Command Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated or encrypted scripts.

T1027.012
LNK Icon Smuggling
GroupGamaredon Group

Gamaredon Group has used LNK files to hide malicious scripts for execution.

T1041
Exfiltration Over C2 Channel
GroupGamaredon Group

A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server.

T1047
Windows Management Instrumentation
GroupGamaredon Group

Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`.

T1057
Process Discovery
GroupGamaredon Group

Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer.

T1059.001
PowerShell
GroupGamaredon Group

Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload.

T1059.005
Visual Basic
GroupGamaredon Group

Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe.

T1082
System Information Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server.

T1083
File and Directory Discovery
GroupGamaredon Group

Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host.

T1090.003
Multi-hop Proxy
GroupGamaredon Group

Gamaredon Group has used Tor for C2 traffic.

T1091
Replication Through Removable Media
GroupGamaredon Group

Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host.

T1095
Non-Application Layer Protocol
GroupGamaredon Group

Gamaredon Group has used SOCKS5 over port 9050 for C2 communication.

T1102.002
Bidirectional Communication
GroupGamaredon Group

Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain.

T1112
Modify Registry
GroupGamaredon Group

Gamaredon Group has removed security settings for VBA macro execution by changing registry values HKCU\Software\Microsoft\Office\<version>\<product>\Security\VBAWarnings and HKCU\Software\Microsoft\Office\<version>\<product>\Security\AccessVBOM. Gamaredon Group has also modified Registry keys to hide folders and system files and to add the C2 address under `HKEY_CURRENT_USER\Console\WindowsUpdate`.

T1113
Screen Capture
GroupGamaredon Group

Gamaredon Group's malware can take screenshots of the compromised computer every minute.

T1218.005
Mshta
GroupGamaredon Group

Gamaredon Group has used `mshta.exe` to execute malicious files.

T1518.001
Security Software Discovery
GroupGamaredon Group

Gamaredon Group has used PowerShell scripts to identify security software on the victim machine.

T1583.001
Domains
GroupGamaredon Group

Gamaredon Group has registered multiple domains to facilitate payload staging and C2.

T1583.006
Web Services
GroupGamaredon Group

Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes.

T1620
Reflective Code Loading
GroupGamaredon Group

Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.