GamaCopy targets Russia's defense sector by mimicking Gamaredon TTPs and using Russian-language military lures.
Analyst brief
GamaCopy is a threat actor targeting Russia's defense and critical infrastructure sectors by mimicking Gamaredon's TTPs. It uses Russian-language bait documents related to military facilities as lures. The actor leverages open-source tools, using 7z-SFX archives to deploy UltraVNC for C2 communication over port 443. Defenders should focus on detecting military-themed phishing documents, unexpected 7z-SFX execution, and suspicious VNC traffic on port 443.
GamaCopy
unknown
GamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimicking the TTPs of Gamaredon. The organization has been active since at least August 2021 and primarily uses Russian-language bait documents related to military facilities. Analysis of attack samples shows considerable overlap in code structure and tactics, including the use of 7z-SFX documentation to install UltraVNC and connecting via port 443. GamaCopy employs open-source tools to obfuscate its activities while targeting sensitive information in the context of the Russia-Ukraine conflict.