Gamaredon's multi-stage malware framework unpacked

In a three-part analysis, Sekoia examines the evolving malware ecosystem used by Gamaredon, a Russia-linked threat actor targeting Ukraine. The campaign relies on a layered infection chain beginning with phishing documents (GammaPhish), followed by loaders and downloaders (GammaLoad) that deploy additional payloads, culminating in GammaSteel, an information-stealing malware designed to collect documents, credentials and system data. The research highlights extensive use of obfuscation, multi-stage payload delivery and rapidly changing infrastructure to maintain persistence and complicate detection.

What this means for your organisation

Chains of this kind are not geographically limited in technique, only in target selection. The approach, an attachment that launches a loader which later retrieves the stealer itself, is the same one that reaches organisations elsewhere in less targeted campaigns. What distinguishes the actor is persistence and infrastructure, and that requires detection which sees the connection between stages rather than the individual file alone.

Berigo recommends

  • Build detection around behaviour in the chain, such as office applications launching scripting engines, not only known file signatures.
  • Restrict macros and script execution from externally received documents through central policy.
  • Log and retain outbound network traffic long enough that a foothold can be traced backwards in time.
  • Exercise a scenario in which the first link in the chain was discovered only after several weeks.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch