DarkGaboon is a financially motivated independent APT group active since May 2023.
Analyst brief
DarkGaboon is a financially motivated APT group operating independently since May 2023. They primarily target Russian organizations using phishing emails to deliver Revenge RAT and LockBit 3.0 ransomware. Their TTPs include homoglyph file names and decoy documents from Russian templates for evasion. Defenders should focus on email security, unusual characters in file names, and monitor traffic to C2 infrastructure located outside Russia.
DarkGaboon
Vengeful Wolfroom155
unknown
DarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily using phishing emails to deliver malware such as Revenge RAT and LockBit 3.0 ransomware. Their operations demonstrate advanced operational security practices, including the use of homoglyphs in file names and decoy documents sourced from legitimate Russian templates to evade detection. The group has shown a disciplined approach to updating their toolkit, with 369 unique files identified, and employs command-and-control infrastructure located outside Russia. DarkGaboon's linguistic proficiency in Russian suggests a deep understanding of the local context, enhancing the effectiveness of their phishing lures.
What is the motivation behind the DarkGaboon APT group and who are their primary targets?+
DarkGaboon is a financially motivated APT group. They have been operating independently since May 2023, primarily targeting Russian organizations.
What tactics does DarkGaboon use to evade detection mechanisms?+
They use homoglyph characters in file names and decoy documents sourced from legitimate Russian templates to evade detection. Defenders should pay special attention to unusual characters in file names.