None
EN
Gamaredon in 2024: Cranking out spearphishing campaigns against Ukraine with an evolved toolset
[]
WeLiveSecurity
While previous years saw occasional attempts against targets in other NATO countries, during 2024 Gamaredon operators returned their focus exclusively to Ukrainian institutions.
Throughout 2024, Gamaredon operators repeatedly updated the tool, introducing new external platforms such as Codeberg repositories to dynamically distribute command and control (C&C) server information, complicating defensive measures.
Throughout 2024, Gamaredon operators repeatedly updated the tool, introducing new external platforms such as Codeberg repositories to dynamically distribute command and control (C&C) server information, complicating defensive measures.
Despite observable capacity limitations and abandoning older tools, Gamaredon remains a significant threat actor due to its continuous innovation, aggressive spearphishing campaigns, and persistent efforts to evade detections.
For a detailed technical breakdown of Gamaredon’s 2024 activities, updates, and malware analyses, read our full white paper.
['gamaredons'
'tools'
'ukraine'
'2024'
'cranking'
'gamaredon'
'vbscript'
'files'
'discovered'
'introduced'
'powershell'
'campaigns'
'spearphishing'
'file'
'toolset'
'evolved']