Menu
Browse
Date:

Dec 2019

Location:

Ukraine

Summary

The Gamaredon APT group, linked to Russian military interests, conducted cyber-espionage and reconnaissance operations against Ukrainian national security targets, including the Hetman Petro Sahaidachnyi National Ground Forces Academy. The attackers deployed an enhanced malware toolset featuring modified Pterodo implants packaged as self-extracting archives, which executed obfuscated .NET components and macro payloads to collect system data, establish persistence, and evade detection through forged certificates and registry manipulation. Campaigns leveraged Nginx forwarders and dynamic DNS infrastructure, impacting over 5,000 Ukrainian entities, with activities extending to physical military hardware and field artillery systems as part of broader hybrid warfare efforts in the region.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In December 2019, Gamaredon APT intensified cyber operations against Ukrainian military and security institutions, including reconnaissance activities targeting the Hetman Petro Sahaidachnyi National Ground Forces Academy. The group deployed malware implants across Ukrainian governmental entities, compromising over 5,000 unique victims near the separatist conflict line in eastern Ukraine. Attacks expanded beyond traditional cyber-espionage to target physical military infrastructure, including field artillery systems. SentinelLabs researchers documented the campaign's evolution, noting Gamaredon's upgraded toolset featured modified Pterodo malware distributed via self-extracting ZIP archives. These archives contained batch scripts, .NET components, and macro payloads designed to conduct system reconnaissance. The malware collected host data, established persistent communication with command-and-control servers, and awaited additional operational directives from attackers.

Cyber Incident Image

The updated Pterodo variant incorporated Microsoft.Vbe.Interop for enhanced macro execution, utilizing obfuscated .NET applications to bypass security measures. Attackers manipulated registry settings to disable Visual Basic for Applications warnings and enable macro execution without user alerts. Malware components employed forged Microsoft Time-Stamp Service digital certificates to appear legitimate. Gamaredon infrastructure utilized Nginx forwarders and dynamic DNS providers to route victim traffic, complicating detection efforts. Campaign analysis confirmed the group's exclusive focus on Ukrainian national security targets, with compromised systems spanning government agencies and military training institutions. The operations demonstrated integration of cyber capabilities with conventional battlefield tactics in the ongoing eastern Ukraine conflict zone since 2014.

Sources
Sources available to members
1 source