The Computer Emergency Response Team (CERT-UA) of Ukraine warns that Gamaredon hackers act very quickly in their attacks , as they manage to steal data from compromised systems in less than an hour after the breach.

Gamaredon, also known as Armageddon , UAC-0010 , and Shuckworm , is a Russian state-sponsored cyberespionage group . Its members have been linked to the Russian Federal Security Service (FSB) and are said to include former SSU officers who defected to Russia in 2014.
Since the beginning of the Russian invasion, these hackers are believed to have carried out thousands of attacks against the government and other important public and private organizations in Ukraine.
See also: AVrecon malware infects 70,000 Linux routers to create botnet
Data collected from these attacks allowed CERT-UA to describe the group and its attacks. data is being shared to help network defenders detect and prevent further breach.
Gamaredon hackers: Attacks
The Gamaredon group's attacks usually begin with an email or message sent to victims via Telegram, WhatsApp, Signal, or other IM apps.
Initial infection is achieved by opening malicious attachments, such as HTM, HTA, and LNK files disguised as Microsoft Word or Excel documents.
When the victim opens the malicious attachments, PowerShell scripts and malware, which is usually “GammaSteel,” are executed on the victim’s device.
The initial infection step allows the modification of Microsoft Office Word templates, so that all documents created on the infected computer carry a malicious macro that can spread the Gamaredon hackers' malware to other systems.
The PowerShell script targets browser cookies that contain session data. This allows hackers to gain access to accounts protected by two-factor authentication.
See also: TeamTNT's Cloud Credential Theft Campaign Now Targets Azure and Google Cloud
Regarding the functionality of the GammaSteel malware, CERT-UA says that it targets files with specific extensions: .doc, .docx, .xls, .xlsx, .rtf, .odt, .txt, .jpg, .jpeg, .pdf, .ps1, .rar, .zip, .7z, .mdb.
If attackers are interested in the documents on a victim's computer, they steal them within 30-50 minutes.
Furthermore, according to CERT-UA, Gamaredon hackers install up to 120 maliciously infected files per week on the compromised system to increase the likelihood of re-infection.

Any USB sticks inserted into the ports of an infected computer will automatically become infected, which could lead to the infection of other devices.
Finally, hackers change the IP addresses of intermediate victims' command and control servers three to six times a day, making it more difficult for defenders to block or detect malicious activities.
According to CERT-UA, the best way to limit the effectiveness of the attacks of the Russian hackers Gamaredon is to block or restrict the unauthorized execution of mshta.exe, wscript.exe, cscript.exe, and powershell.exe.
See also: Shutterfly: Clop ransomware attack did not affect customer data
Malware attacks pose a serious threat to devices and networks, but by keeping systems up to date and following best practices, we can protect ourselves to some extent. Remember to keep your software up to date, use antivirus software , be cautious when opening email attachments, and back up your files regularly. By following these simple steps, you can protect your digital life and keep your data safe from cybercriminals.
Source: www.bleepingcomputer.com
