The Russia-linked hackers, known as «Gamaredon» – a group also known as Armageddon or Shuckworm – were found to be developing eight custom binaries for cyber‑espionage operations against Ukrainian entities.
See also: Belarus: Ransomware attack on railways as protest

This hacking group is believed to operate directly from the Russian FSB (Federal Security Service) and is responsible for thousands of attacks in Ukraine since 2013.
See also: Russia: Charges 8 gang members suspected of REvil ransomware
Researchers in the Threat Hunter team at Symantec, part of Broadcom Software, analyzed eight malware samples used by the Gamaredon group against Ukrainian targets in recent attacks, which could provide defenders with essential information for protection against ongoing attacks.
Files used in recent Gamaredon attacks
According to the Symantec report, the monitored attacks started in July with the spread of spear-phishing emails that carried Word documents with macros.
These files released a VBS file that launched the “Pteranodon”, a well-documented backdoor that Gamaredon has been developing and improving for almost seven years.
However, while recent attacks continue to be carried out using phishing emails, these attacks appear to now disperse eight different payloads, as described below.
All eight files sampled by Symantec analysts from recent Gamaredon attacks are 7-zip self-extracting binaries that minimize user interaction requirements.
- descend.exe – Runs to drop a VBS file into “%USERPROFILE%\Downloads\deerbrook.ppt” and “%PUBLIC%\Pictures\deerbrook.ppt” and creates a scheduled task on the compromised system. The VBS contacts the C2 and “delivers” the payload.
- deep-sunken.exe – The downloaded payload is executed to drop four more files on the compromised computer: baby.cmd, baby.dat, basement.exe (wget binary), vb_baby.vbs. A new scheduled task is created and the C2 is contacted again for the next payload.
- z4z05jn4.egf.exe – Next-stage payload that is similar to the previous one but has a different C2, drops files in different folders, and uses different file names.
- defiant.exe – Runs to drop VBS files into “%TEMP%\\deep-versed.nls” and “%PUBLIC\Pictures\deep-versed.nls” and then creates a scheduled task to execute them.
- deep-green.exe – UltraVNC remote management tool that connects to a repeater.
- deep-green.exe – Process Explorer binary for Microsoft Windows.
- deep-green.exe – Same as defiant.exe but with different C2 encoding and file names.
- deep-green.exe – Drops VBS in “%PUBLIC%\Music\” and creates a scheduled task that searches for removable drives on the infected system.
Other indicators of compromise include URLs and C2 IP addresses assigned by AS9123 TimeWeb Ltd., all of which use a unique URI structure as shown below:
- http + IP + /.php?=, OR
- http + IP + /.php?=,-
See also: Belarusian government is responsible for Ghostwriter campaigns
Also, the most common directories that host malicious files are:
- csidl_profile\\links
- csidl_profile\\searches
- CSIDL_PROFILE\\appdata\\local\\temp\\
- CSIDL_PROFILE\\

The Symantec report concludes that many of the discarded files have unknown parent process hashes that were not analyzed, therefore parts of the Gamaredon operation remain unclear.
The file hashes for the new malware payloads discovered by Symantec can be found in their report.
Information source: bleepingcomputer.com
