Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Gammarderson uses an infected removable drive to infringe Ukraine’s western military mission
Celebrities

Gammarderson uses an infected removable drive to infringe Ukraine’s western military mission

By April 10, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 10, 2025Ravi LakshmananCyber ​​Spy/Malware

Western military violations

The Russian-related threat actor, known as Gammerderson (aka Shuckworm), is attributed to a cyber attack targeting foreign military missions based in Ukraine, with the aim of providing an updated version of the known malware called Gammasteel.

The group targeted military missions in the Western country, according to the Symantec Threat Hunter team, along with the first indication of malicious activity detected on February 26, 2025.

“It appears that the first infection vector used by the attacker was an infected removable drive,” the threat intelligence division owned by Broadcom said in a report shared with Hacker News.

Cybersecurity

The attack started with creating a Windows registry value under the user assist key, then launched “Mshta.exe” using “Explorer.exe” to start a multistage infection chain, launching two files.

The first file named “ntuser.dat.tmcontainer0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

The second file in question, “ntuser.dat.tmcontainer00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

Then, on March 1, 2025, the script runs to contact the C2 server, removes system metadata, and receives a Base64-encoded payload in return. This is used to run PowerShell commands designed to download new obfuscated versions of the same script.

This script connects to a hardcoded C2 server and gets two more PowerShell scripts. The first is a reconnaissance utility that can capture screenshots, run the SystemINFO command, get details of the security software running on the host, enumerate files and folders on the desktop, and a wrist-running process.

The second PowerShell script is an improved version of Gammasteel, a known information sturler that can remove files from victims based on extension lists from desktop and document folders.

Cybersecurity

“This attack marks something like an increase in the refinement of Shuckworm, who appears to be less skilled than other Russian actors, but compensates for this by mercilessly focusing on Ukrainian targets,” Symantec says.

“While the group doesn’t appear to have access to the same skill set as other Russian groups, it appears Shuckworm is trying to compensate for this by continuously changing the code it uses, adding obfuscation, and leveraging legitimate web services to reduce the risk of detection.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAI Insurtech Ominimo bags first investment at a $220 million valuation
Next Article How the UK nuclear task force speeds up the nuclear renaissance

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

Trending Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

June 16, 2026

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.