Full Report
A little-known hacking group has been mimicking the tactics of a prominent Kremlin-linked threat actor to target Russian-speaking victims, according to new research.
Analysis Summary
# Threat Actor: GamaCopy
## Attribution & Identity
* **Primary Identification:** GamaCopy (a little-known hacking group).
* **Attribution Theory:** Researchers suggest GamaCopy is most likely linked to the state-backed actor **Core Werewolf**, though its definitive national association is unknown.
* **Mimicry:** The group is actively mimicking the tactics of the prominent Kremlin-linked threat actor **Gamaredon**.
## Activity Summary
* **Recent Campaign:** Used phishing documents disguised as official reports concerning the location of Russian armed forces’ facilities in Ukraine, targeting Russian-speaking victims.
* **Campaign Description:** Described by Knownsec as a "successful false flag operation" due to its imitation of Gamaredon.
* **Historical Activity:** First discovered by Knownsec in June 2023, believed to be active since at least August 2021.
## Tactics, Techniques & Procedures
* **Email/Phishing:** Delivered malicious content via phishing documents leveraging Russian-language lures (contrasting with Gamaredon's Ukrainian lures).
* **Execution:** Used the self-opening 7-Zip file archiver (**7zSFX**) to deliver and load subsequent payloads.
*
* **Remote Access:** Deployed the open-source remote access tool **UltraVNC** to gain remote control over compromised systems.
* **Association:** The use of 7zSFX and UltraVNC is also associated with Core Werewolf.
## Targeting
* **Sectors:** Russia’s defense sector and critical infrastructure.
* **Geography:** Focused on Russian-speaking victims, implying activity within or against Russian interests.
* **Victims:** Not specifically named, but the victims belong to the defense and critical infrastructure sectors within Russia.
## Tools & Infrastructure
* **Malware families used:** UltraVNC (open-source software), 7zSFX (self-extracting archive).
* **Infrastructure (C2, domains, IPs):** Not detailed in the provided context.
## Implications
GamaCopy presents a significant operational security challenge as it deliberately obscures its true origins by mimicking tactics associated with the well-known, FSB-linked Gamaredon. This intentional false-flagging complicates attribution efforts and allows the actor (most likely Core Werewolf) to operate within sensitive Russian sectors while deflecting investigation toward a known Russian entity.
## Mitigations
* **Lure Awareness:** Be highly skeptical of documents disguised as official reports, particularly concerning military locations, even if written in Russian.
* **Application Control:** Monitor and restrict the execution of non-standard remote access tools like UltraVNC on critical systems.
* **Archive Analysis:** Implement security measures to inspect or sandbox self-extracting archives (.7zSFX) before execution on endpoints, as this is a known delivery mechanism utilized by associated threat groups.