Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Sheryl Crow calls Trump’s UFC B-Day brawl on the White House lawn ‘disgraceful’

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Russia-related Gamalen deploys Remcos Rat to Ukraine using force-related lures
Celebrities

Russia-related Gamalen deploys Remcos Rat to Ukraine using force-related lures

By March 31, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 31, 2025Ravi LakshmananThreat Intelligence/Malware

Deploying Remcos Rat in Ukraine

The Ukrainian entities are being targeted as part of a phishing campaign designed to distribute remote access trojans called Remcos Rat.

“The filename uses Russian as the lure, which is related to the movement of the Ukrainian military,” Cisco Talos researcher Guilherme Venere said in a report released last week. “PowerShell Downloader will contact Geofence servers located in Russia and Germany to download the second stage ZIP file, including the REMCOS backdoor.”

This activity is attributed to a Russian hacking group known as Gamaredon with moderate confidence. This is also tracked under Aqua Blizzard, Armageddon, Blue Otso, Bluealpha, Hive0051, Iron Tilden, Primitive Bear, Shuckworm, Trident URSA, UAC-0010, UNC530, and winter seasons.

Cybersecurity

Threat leaders, rated as affiliated with the Russian Federation Security Bureau (FSB), are known for targeting Ukrainian organisations on spying and data theft. It has been operational since at least 2013.

The latest campaign features the distribution of compressed Windows Shortcuts (LNK) files within a ZIP archive, which impersonates them as Microsoft Office Documents related to the ongoing Russo-Ukrainian War to open recipients. These archives are thought to be sent via phishing email.

The link to Gamaredon is attributed to the use of two machines that were used to create malicious shortcut files and previously used for similar purposes by threat actors.

The LNK file is equipped with PowerShell code responsible for downloading and running the next stage payload CMDLET Get-Command, and repeats retrieving the decoy file that is displayed to the victim.

The second stage is a separate ZIP archive, which contains malicious DLLs that are executed via a technique called DLL sideloading. A DLL is a loader that decrypts and executes the final REMCOS payload from encrypted files that reside in an archive.

This disclosure comes as Silent Push has detailed its phishing campaign and has come to use website lures to collect information about Russian individuals sympathetic to Ukraine. This activity is considered to be the work of either the Russian Intelligence Agency or the threat actor alongside Russia.

Cybersecurity

The campaign consists of four major phishing clusters, consisting of the US Central Intelligence Agency (CIA), Russian volunteer squadrons, Legion Liberty, and Hochujit, “I Want to Live.”

We found that the phishing page is hosted on bulletproof hosting provider Nybula LLC, as threat actors rely on Google Forms and email responses to collect personal information from victims.

“All campaigns […] What was observed has similar properties and shares a common purpose. Silent Push said that he will collect personal information from victims visiting the site.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFrench court convicts far-right leader Le Pen for embezzlement | far-right news
Next Article LHCB experiments reveal mysterious clues to matter and attitude

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Sheryl Crow calls Trump’s UFC B-Day brawl on the White House lawn ‘disgraceful’

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Trending Posts

Sheryl Crow calls Trump’s UFC B-Day brawl on the White House lawn ‘disgraceful’

June 16, 2026

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

June 16, 2026

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.