CSIDB logo
Incident

Hetman Petro Sahaidachnyi National Ground Forces Academy

Incident posture

Attack window
Dec 2019
Location
Ukraine
Status
Historical
CIA posture
Available to members
Updated
2025-11-02 00:00

Linked entities

Victim
Hetman Petro Sahaidachnyi National Ground Forces Academy
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Gamaredon APT group, linked to Russian military interests, conducted cyber-espionage and reconnaissance operations against Ukrainian national security targets, including the Hetman Petro Sahaidachnyi National Ground Forces Academy. The attackers deployed an enhanced malware toolset featuring modified Pterodo implants packaged as self-extracting archives, which executed obfuscated .NET components and macro payloads to collect system data, establish persistence, and evade detection through forged certificates and registry manipulation. Campaigns leveraged Nginx forwarders and dynamic DNS infrastructure, impacting over 5,000 Ukrainian entities, with activities extending to physical military hardware and field artillery systems as part of broader hybrid warfare efforts in the region.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In December 2019, Gamaredon APT intensified cyber operations against Ukrainian military and security institutions, including reconnaissance activities targeting the Hetman Petro Sahaidachnyi National Ground Forces Academy. The group deployed malware implants across Ukrainian governmental entities, compromising over 5,000 unique victims near the separatist conflict line in eastern Ukraine. Attacks expanded beyond traditional cyber-espionage to target physical military infrastructure, including field artillery systems. SentinelLabs researchers documented the campaign's evolution, noting Gamaredon's upgraded toolset featured modified Pterodo malware distributed via self-extracting ZIP archives. These archives contained batch scripts, .NET components, and macro payloads designed to conduct system reconnaissance. The malware collected host data, established persistent communication with command-and-control servers, and awaited additional operational directives from attackers.

The updated Pterodo variant incorporated Microsoft.Vbe.Interop for enhanced macro execution, utilizing obfuscated .NET applications to bypass security measures. Attackers manipulated registry settings to disable Visual Basic for Applications warnings and enable macro execution without user alerts. Malware components employed forged Microsoft Time-Stamp Service digital certificates to appear legitimate. Gamaredon infrastructure utilized Nginx forwarders and dynamic DNS providers to route victim traffic, complicating detection efforts. Campaign analysis confirmed the group's exclusive focus on Ukrainian national security targets, with compromised systems spanning government agencies and military training institutions. The operations demonstrated integration of cyber capabilities with conventional battlefield tactics in the ongoing eastern Ukraine conflict zone since 2014.

Sources

Sources available to members: 1 source.

CSIDB