Armenian Deposit Guarantee Fund
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
The Armenian Deposit Guarantee Fund, also known by the acronym ADGF, is a financial‑sector institution based in Armenia. Its primary mandate is to guarantee eligible bank deposits held by individuals and entities within the Armenian banking system. By providing this guarantee, the fund aims to maintain public confidence in the banking sector and contribute to overall financial stability. The organisation operates under the legal framework established by Armenian deposit‑insurance legislation. On 1 January 2019, the ADGF’s online presence was compromised as part of a broader watering‑hole attack that affected several Armenian websites.
Attackers injected malicious JavaScript code into the compromised sites, which executed when visitors loaded the pages. The script presented a false Adobe Flash update prompt, attempting to trick users into downloading and executing malware. The campaign was later attributed to the Turla group, a known cyber‑espionage actor linked to state‑sponsored activities. As part of the operation, the attackers deployed persistent tracking mechanisms that fingerprinted visitors’ browsers and system configurations. Fingerprinting enabled the threat actors to identify high‑value visitors, such as employees of governmental organisations, for selective targeting.
The initial malware payload delivered to compromised hosts was the Skipper backdoor, a previously documented remote‑access tool. Later phases of the attack saw the Skipper backdoor supplanted by a new .NET‑based malware family named NetFlash. Concurrently, a Python‑based variant referred to as PyFlash was introduced to diversify the infection vectors. Both NetFlash and PyFlash were engineered to evade detection by conventional antivirus and endpoint‑protection solutions. Once installed, the malware collected detailed system information, including hardware specifications, installed software, and network configuration.
The collected data was then exfiltrated to attacker‑controlled command‑and‑control servers to support espionage objectives. Notably, the intrusion relied entirely on social engineering tactics rather than exploiting software vulnerabilities. The primary victims of the campaign were Armenian governmental entities, which the attackers sought to monitor and extract sensitive information from. By compromising a deposit‑guarantee‑fund‑related website, the attackers gained a foothold that could be leveraged to target users interested in financial‑sector communications. The incident underscored how watering‑hole techniques can be used to infiltrate organisations perceived as trustworthy within a national critical‑infrastructure context.
No explicit details regarding the ADGF’s staff size, annual budget, or precise organisational structure are disclosed in the sources consulted. Similarly, information about any parent organisation, subsidiary entities, or ownership structure is not provided in the available material. The fund’s regulatory role is to ensure that depositors receive compensation up to a statutory limit when a participating bank becomes insolvent. This function places the ADGF within Armenia’s broader financial‑safety‑net architecture, alongside the central bank and other supervisory authorities. Consequently, the ADGF’s operations are governed by national legislation and are subject to oversight by the Armenian financial‑regulatory framework.
Incidents
1 incident linked to this organisation.