[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/gamaredon-primitive-bear-ukraine-update-2021/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Russia's Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 15 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 3, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/)
  * [Gamaredon](https://unit42.paloaltonetworks.com/tag/gamaredon/)
  * [Primitive bear](https://unit42.paloaltonetworks.com/tag/primitive-bear/)
  * [Russia](https://unit42.paloaltonetworks.com/tag/russia/)
  * [Trident Ursa](https://unit42.paloaltonetworks.com/tag/trident-ursa/)
  * [Ukraine](https://unit42.paloaltonetworks.com/tag/ukraine/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Russia’s%20Gamaredon%20aka%20Primitive%20Bear%20APT%20Group%20Actively%20Targeting%20Ukraine&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fgamaredon-primitive-bear-ukraine-update-2021%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fgamaredon-primitive-bear-ukraine-update-2021%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fgamaredon-primitive-bear-ukraine-update-2021%2F&title=Russia’s%20Gamaredon%20aka%20Primitive%20Bear%20APT%20Group%20Actively%20Targeting%20Ukraine "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fgamaredon-primitive-bear-ukraine-update-2021%2F&text=Russia’s%20Gamaredon%20aka%20Primitive%20Bear%20APT%20Group%20Actively%20Targeting%20Ukraine "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fgamaredon-primitive-bear-ukraine-update-2021%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Russia’s%20Gamaredon%20aka%20Primitive%20Bear%20APT%20Group%20Actively%20Targeting%20Ukraine%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fgamaredon-primitive-bear-ukraine-update-2021%2F "Share in Mastodon")

## Executive Summary

Since November, geopolitical tensions between Russia and Ukraine have escalated dramatically. It is estimated that Russia has now amassed over 100,000 troops on Ukraine's eastern border, leading some to speculate that an invasion may come next. On Jan. 14, 2022, this conflict spilled over into the cyber domain as the Ukrainian government was targeted with destructive malware ([WhisperGate](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/)) and a separate vulnerability in OctoberCMS was exploited to deface several Ukrainian government websites. While attribution of those events is ongoing and there is no known link to [Gamaredon](https://unit42.paloaltonetworks.com/tag/gamaredon/) (aka Primitive Bear), one of the most active existing advanced persistent threats targeting Ukraine, we anticipate we will see additional malicious cyber activities over the coming weeks as the conflict evolves. We have also observed recent activity from Gamaredon. In light of this, this blog provides an update on the Gamaredon group.

Since 2013, just prior to Russia's annexation of the Crimean peninsula, the Gamaredon group has primarily focused its cyber campaigns against Ukrainian government officials and organizations. In 2017, Unit 42 published its first research [documenting Gamaredon's evolving toolkit](https://unit42.paloaltonetworks.com/unit-42-title-gamaredon-group-toolset-evolution/) and naming the group, and over the years, several researchers have noted that the operations and targeting activities of this group align with Russian interests. This link was recently substantiated on Nov. 4, 2021, when the Security Service of Ukraine (SSU) [publicly attributed](https://www.bleepingcomputer.com/news/security/ukraine-links-members-of-gamaredon-hacker-group-to-russian-fsb/) the leadership of the group to five Russian Federal Security Service (FSB) officers assigned to posts in Crimea. Concurrently, the SSU also released an updated [technical report](https://ssu.gov.ua/uploads/files/DKIB/Technical%20report%20Armagedon.pdf) documenting the tools and tradecraft employed by this group.

Given the current geopolitical situation and the specific target focus of this APT group, Unit 42 continues to actively monitor for indicators of their operations. In doing so, we have mapped out three large clusters of their infrastructure used to support different phishing and malware purposes. These clusters link to over 700 malicious domains, 215 IP addresses and over 100 samples of malware.

Monitoring these clusters, we observed an attempt to compromise a Western government entity in Ukraine on Jan. 19, 2022. The sections below offer an overview of our findings in order to aid targeted entities in Ukraine as well as cybersecurity organizations in defending against this threat group.

**Update Feb. 16:** When we originally published this report, we noted, "While we have mapped out three large clusters of currently active Gamaredon infrastructure, we believe there is more that remains undiscovered." We have since discovered hundreds more Gamaredon-related domains, including known related-clusters, and also new clusters. We have updated our [Indicators of Compromise (IoCs)](https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/#indicators-of-compromise) to include these additional domains and cluster observations.

**Update June 22:** As noted in February, Unit 42 continues to monitor and research Gamaredon infrastructure and malware. Today we are sharing another update to our [Gamaredon IoCs](https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/#indicators-of-compromise), listing infrastructure that we have observed since the previous update.

Full visualization of the techniques observed, relevant courses of action and IoCs related to this Gamaredon report can be found in the [Unit 42 ATOM viewer](https://unit42.paloaltonetworks.com/atoms/gamaredon/).

Palo Alto Networks customers receive protections against the types of threats discussed in this blog by products including [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and the [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire), [AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus), [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [DNS Security](https://www.paloaltonetworks.com/network-security/dns-security) subscription services for the [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall).

|------------------------|-----------------------------------------------------------------------------------------------------------------------|
| Related Unit 42 Topics | [Gamaredon](https://unit42.paloaltonetworks.com/tag/gamaredon/), [APTs](https://unit42.paloaltonetworks.com/tag/APT/) |

## Gamaredon Downloader Infrastructure (Cluster 1)

Gamaredon actors pursue an interesting approach when it comes to building and maintaining their infrastructure. Most actors choose to discard domains after their use in a cyber campaign in order to distance themselves from any possible attribution. However, Gamaredon's approach is unique in that they appear to recycle their domains by consistently rotating them across new infrastructure. A prime example can be seen in the domain libre4\[.\]space. Evidence of its use in a Gamaredon campaign was flagged by a [researcher](https://twitter.com/Timele9527/status/1118343183971360769) as far back as 2019. Since then, [Cisco Talos](https://blog.talosintelligence.com/2021/02/gamaredonactivities.html) and [Threatbook](https://x.threatbook.cn/v5/article?threatInfoID=1417) have also firmly attributed the domain to Gamaredon. Yet despite public attribution, the domain continues to resolve to new internet protocol (IP) addresses daily.

![The screenshot shows IP addresses to which a domain known to be associated with Gamaredon resolves. This is a prime example of an approach used by the APT, in which they recycle domains by consistently rotating them across new infrastructure.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image.png) Figure 1. libre4\[.\]space recent IP resolutions as of Jan. 27, 2022. Pivoting to the first IP on the list (194.58.100\[.\]17) reveals a cluster of domains rotated and parked on the IP on the exact same day.

![Continuing the example of rotating domains across new infrastructure, this screenshot shows a cluster of domains rotated and parked on an IP address, all on the exact same day.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image-1.png) Figure 2. Domains associated with 194.58.100\[.\]17 on Jan. 27, 2022. Thorough pivoting through all of the domains and IP addresses results in the identification of almost 700 domains. These are domains that are already publicly attributed to Gamaredon due to use in previous cyber campaigns, mixed with new domains that have not yet been used. Drawing a delineation between the two then becomes an exercise in tracking the most recent infrastructure.

Focusing on the IP addresses linked to these domains over the last 60 days results in the identification of 136 unique IP addresses; interestingly, 131 of these IP addresses are hosted within the autonomous system (AS) 197695 physically located in Russia and operated by the same entity used as the registrar for these domains, reg\[.\]ru. The total number of IPs translates to the introduction of roughly two new IP addresses every day into Gamaredon's malicious infrastructure pool. Monitoring this pool, it appears that the actors are activating new domains, using them for a few days, and then adding the domains to a pool of domains that are rotated across various IP infrastructure. This shell game approach affords a degree of obfuscation to attempt to hide from cybersecurity researchers.

For researchers, it becomes difficult to correlate specific payloads to domains and to the IP address that the domain resolved to on the precise day of a phishing campaign. Furthermore, Gamaredon's technique provides the actors with a degree of control over who can access malicious files hosted on their infrastructure, as a web page's uniform resource locator (URL) file path embedded in a downloader only works for a finite period of time. Once the domains are rotated to a new IP address, requests for the URL file paths will result in a "404" file not found error for anyone attempting to study the malware.

### Cluster 1 History

While focusing on current downloader infrastructure, we were able to trace the longevity of this cluster back to an origin in 2018. Certain "marker" domains, such as the aforementioned libre4\[.\]space, are still active today and also traced back to March 2019 with apparently consistent ownership. On the same date range in March 2019, a cluster of domains was observed on 185.158.114\[.\]107 with thematically linked naming -- several of which are still active in this cluster today.

![The screenshot shows a cluster of domains observed an an IP address with thematically linked naming - several of which are still active in this cluster today.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image-2.png) Figure 3. Domain cluster on 185.158.114\[.\]107 in March 2019. Further pivoting back in time and across domains finds an apparent initial domain for this cluster of infrastructure, bitsadmin\[.\]space on 195.88.209\[.\]136, in December 2018.

![The screenshot shows an apparent initial domain used by Gamaredon used by this cluster of infrastructure.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image-3.png) Figure 4. Initial domain bitsadmin\[.\]space, December 2018. We see it clustered here with some dynamic domain name system (DNS) domains. Dynamic DNS domains were observed in this cluster on later IP addresses as well, though this technique appears to have fallen out of favor, at least in this context, since there are none in this cluster currently active.

### Initial Downloaders

Searching for samples connecting to Gamaredon infrastructure across public and private malware repositories resulted in the identification of 17 samples over the past three months. The majority of these files were either shared by entities in Ukraine or contained Ukrainian filenames.

|-----------------------------------------------------------------|-----------------------------------------------------------------------|
| **Filename**                                                    | **Translation**                                                       |
| Максим.docx                                                     | Maksim.docx                                                           |
| ПІДОЗРА РЯЗАНЦЕВА.docx                                          | RAZANTSEV IS SUSPICIOUS.docx                                          |
| протокол допиту.docx                                            | interrogation protocol.docx                                           |
| ТЕЛЕГРАММА.docx                                                 | TELEGRAM.docx                                                         |
| 2\_Пам'ятка\_про\_процесуальні\_права\_та\_обов'язки\_потерпілого.docx | 2\_Memorial\_about\_processal\_rights\_and\_obligations\_of\_the\_ Victim.docx |
| 2\_Porjadok\_do\_nakazu\_111\_vid\_13.04.2017.docx                    | 2\_Procedure\_to\_order\_111\_from\_13.04.2017.docx                         |
| висновок тимошечкин.docx                                        | conclusion Timoshechkin.docx                                          |
| Звіт на ДМС за червень 2021 (Автосохраненный).doc               | Report on the LCA for June 2021 (Autosaved) .doc                      |
| висновок Кличко.docx                                            | Klitschko's conclusion.docx                                           |
| Обвинувальний акт ГЕРМАН та ін.docx                            | Indictment GERMAN et al.docx                                          |
| супровід 1-СЛ 10 місяців.doc                                    | support 1-SL 10 months.doc                                            |

*Table 1. Recently observed downloader filenames.*

An analysis of these files found that they all leveraged a remote template injection technique that allows the documents to pull down the malicious code once they are opened. This allows the attacker to have control over what content is sent back to the victim in an otherwise benign document. Recent examples of the remote template "dot" file URLs these documents use include the following:

http://bigger96.allow.endanger.hokoldar\[.\]ru/\[Redacted\]/globe/endanger/lovers.cam  
http://classroom14.nay.sour.reapart\[.\]ru/\[Redacted\]/bid/sour/glitter.kdp  
http://priest.elitoras\[.\]ru/\[Redacted\]/pretend/pretend/principal.dot  
http://although.coferto\[.\]ru/\[Redacted\]/amazing.dot  
http://source68.alternate.vadilops\[.\]ru/\[Redacted\]/clamp/interdependent.cbl

Many of the files hosted on the Gamaredon infrastructure are labeled with abstract extensions such as .cam, .cdl, .kdp and others. We believe this is an intentional effort by the actor to reduce exposure and detection of these files by antivirus and URL scanning services.

Taking a deeper look at the top two, hokoldar\[.\]ru and reapart\[.\]ru, provides unique insights into two recent phishing campaigns. Beginning with the first domain, passive DNS data shows that the domain first resolved to an IP address that was shared with other Gamaredon domains on Jan. 4. Figure 2 above shows that hokoldar\[.\]ru continued to share an IP address with libre4\[.\]space on Jan. 27, once again associating it with the Gamaredon infrastructure pool. In that short window, on Jan. 19, we observed a targeted phishing attempt against a Western government entity operating in Ukraine.

In this attempt, rather than emailing the downloader directly to their target, the actors instead leveraged a job search and employment service within Ukraine. In doing so, the actors searched for an active job posting, uploaded their downloader as a resume and submitted it through the job search platform to a Western government entity. Given the steps and precision delivery involved in this campaign, it appears this may have been a specific, deliberate attempt by Gamaredon to compromise this Western government organization.

Expanding beyond this recent case, we also discovered public evidence of a Gamaredon campaign targeting the State Migration Service of Ukraine. On Dec. 1, an email was sent from yana\_gurina@ukr\[.\]net to 6524@dmsu\[.\]gov.ua. The subject of the email was "NOVEMBER REPORT" and attached to the email was a file called "Report on the LCA for June 2021(Autosaved).doc." When opened, this Word document calls out to reapart\[.\]ru. From there, it downloads and then executes a malicious remote Word Document Template file named glitter.kdp.

![Screenshot of an email associated with public evidence of a Gamaredon campaign targeting the State Migration Service of Ukraine.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image-4.png) Figure 5. Email sent to 6524@dmsu\[.\]gov.ua. CERT Estonia (CERT-EE), a department within the Cyber Security Branch of the Estonian Information System Authority, recently [published an article](https://www.ria.ee/sites/default/files/content-editors/kuberturve/tale_of_gamaredon_infection.pdf) on Gamaredon which covers the content returned from these remote template files. To summarize their findings on this aspect, the remote template retrieves a VBS script to execute which establishes a persistent command and control (C2) check-in and will retrieve the next payload once the Gamaredon group is ready for the next phase. In CERT-EE's case, after six hours the infrastructure came back to life again and downloaded a SelF-eXtracting (SFX) archive.

## SSL Pivot to Additional Infrastructure and Samples

While conducting historical research on the infrastructure in cluster 1, we discovered a self-signed certificate associated with cluster 1 IP address 92.242.62\[.\]96:

Serial: 373890427866944398020500009522040110750114845760  
SHA1: 62478d7653e3f5ce79effaf7e69c9cf3c28edf0c  
Issued: 2021-01-27  
Expires: 2031-01-25  
Common name: ip45-159-200-109.crelcom\[.\]ru

Although the IP Address WHOIS record for Crelcom LLC is registered to an address in Moscow, the technical admin listed for the netblock containing the IP address is registered to an address in Simferopol, Crimea. We further trace the apparent origins of Crelcom back to Simferopol, Crimea, as well.

This certificate relates to 79 IP addresses:

* The common-name IP address - no Gamaredon domains
* One IP address links to cluster 1 above (92.242.62\[.\]96)
* 76 IP addresses link to another distinct collection of domains -- "cluster 2"
* 1 IP address led us to another distinct cluster, "cluster 3" (194.67.116\[.\]67)

We find almost no overlap of IP addresses between these separate clusters.

## File Stealer (Cluster 2)

Of the 76 IP addresses we associate with cluster 2, 70 of them have confirmed links to C2 domains associated with a variant of Gamaredon's file stealer tool. Within the last three months, we have identified 23 samples of this malware, twelve of which appear to have been shared by entities in Ukraine. The C2 domains in those samples include:

|-----------------|----------------|
| **Domain**      | **First Seen** |
| jolotras\[.\]ru | 12/16/2021     |
| moolin\[.\]ru   | 10/11/2021     |
| naniga\[.\]ru   | 9/2/2021       |
| nonimak\[.\]ru  | 9/2/2021       |
| bokuwai\[.\]ru  | 9/2/2021       |
| krashand\[.\]ru | 6/17/2021      |
| gorigan\[.\]ru  | 5/25/2021      |

*Table 3. Recent file stealer C2 domains.*

As you can see, some of these domains were established months ago, yet despite their age, they continue to enjoy benign reputations. For example, only five out of 93 vendors consider the domain krashand\[.\]ru to be malicious on VirusTotal.

![An example of a Gamaredon domain that, despite having been established months ago, enjoys a benign reputation (only five out of 93 vendors consider it to be malicious on VirusTotal as of Jan. 27).](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image-6.png) Figure 7. VirusTotal results for krashand\[.\]ru from Jan. 27, 2022. Reviewing passive DNS (pDNS) logs for these domains quickly reveals a long list of subdomains associated with each. Some of the subdomains follow a standardized pattern. For example, several of the domains use the first few letters of the alphabet (a, b, c) in a repeating combination. Conversely, jolotras\[.\]ru and moolin\[.\]ru use randomized alphanumeric characters. We believe that these subdomains are dynamically generated by the file stealer when it first establishes a connection with its C2 server. As such, counting the number of subdomains associated with a particular C2 domain provides a rough gauge of the number of entities that have attempted to connect to the server. However, it is important to also note that the number of pDNS entries can also be skewed by researchers and cybersecurity products that may be evaluating the malicious samples associated with a particular C2 domain.

|----------------------------------------|
| **Subdomains**                         |
| 637753576301692900\[.\]jolotras.ru     |
| 637753623005957947\[.\]jolotras\[.\]ru |
| 637755024217842817.jolotras\[.\]ru     |
| a.nonimak\[.\]ru                       |
| aaaa.nonimak\[.\]ru                    |
| aaaaa.nonimak\[.\]ru                   |
| aaaaaa.nonimak\[.\]ru                  |
| 0enhzs.moolin\[.\]ru                   |
| 0ivrlzyk.moolin\[.\]ru                 |
| 0nxfri.moolin\[.\]ru                   |

*Table 4. Subdomain naming for file stealer infrastructure.*

In mapping these domains to their corresponding C2 infrastructure, we discovered that the domains overlap in terms of the IP addresses they point to. This allowed us to identify the following active infrastructure:

|--------------------|----------------|
| **IP Address**     | **First Seen** |
| 194.58.92\[.\]102  | 1/14/2022      |
| 37.140.199\[.\]20  | 1/10/2022      |
| 194.67.109\[.\]164 | 12/16/2021     |
| 89.108.98\[.\]125  | 12/26/2021     |
| 185.46.10\[.\]143  | 12/15/2021     |
| 89.108.64\[.\]88   | 10/29/2021     |

*Table 5. Recent file stealer IP infrastructure.*

Of note, all of the file stealer infrastructure appears to be hosted within AS197695, the same AS highlighted earlier. Historically, we have seen the C2 domains point to various autonomous systems (AS) globally. However, as of early November, it appears that the actors have consolidated all of their file stealer infrastructure within Russian ASs -- predominantly this single AS.

In mapping the patterns involved in the use of this infrastructure, we found that the domains are rotated across IP addresses in a manner similar to the downloader infrastructure discussed previously. A malicious domain may point to one of the C2 server IP addresses today while pointing to a different address tomorrow. This adds a degree of complexity and obfuscation that makes it challenging for network defenders to identify and remove the malware from infected networks. The discovery of a C2 domain in network logs thus requires defenders to search through their network traffic for the full collection of IP addresses that the malicious domain has resolved to over time. As an example, moolin\[.\]ru has pointed to 11 IP addresses since early October, rotating to a new IP every few days.

|---------------------|-------------|--------|----------------|---------------|
| **IP Address**      | **Country** | **AS** | **First Seen** | **Last Seen** |
| 194.67.109\[.\]164  | RU          | 197695 | 2021-12-28     | 2022-01-27    |
| 185.46.10\[.\]143   | RU          | 197695 | 2021-12-16     | 2021-12-26    |
| 212.109.199\[.\]204 | RU          | 29182  | 2021-12-15     | 2021-12-15    |
| 80.78.241\[.\]253   | RU          | 197695 | 2021-11-19     | 2021-12-14    |
| 89.108.78\[.\]82    | RU          | 197695 | 2021-11-16     | 2021-11-18    |
| 194.180.174\[.\]46  | MD          | 39798  | 2021-11-15     | 2021-11-15    |
| 70.34.198\[.\]226   | SE          | 20473  | 2021-10-14     | 2021-10-30    |
| 104.238.189\[.\]186 | FR          | 20473  | 2021-10-13     | 2021-10-14    |
| 95.179.221\[.\]147  | FR          | 20473  | 2021-10-13     | 2021-10-13    |
| 176.118.165\[.\]76  | RU          | 43830  | 2021-10-12     | 2021-10-13    |

*Table 6. Recent file stealer IP infrastructure*

Shifting focus to the malware itself, file stealer samples connect to their C2 infrastructure in a unique manner. Rather than connecting directly to a C2 domain, the malware performs a DNS lookup to convert the domain to an IP address. Once complete, it establishes an HTTPS connection directly to the IP address. For example:

C2 Domain: moolin\[.\]ru  
C2 IP Address: 194.67.109\[.\]164  
C2 Comms: https://194.67.109\[.\]164/zB6OZj6F0zYfSQ

This technique of creating distance between the domain and the physical C2 infrastructure seems to be an attempt to bypass URL filtering:

1. The domain itself is only used in an initial DNS request to resolve the C2 server IP address -- no actual connection is attempted using the domain name.
2. Identification and blocking of a domain doesn't impact existing compromises as the malware will continue to communicate directly with the C2 server using the IP address -- even if the domain is subsequently deleted or rotated to a new IP -- as long as the malware continues to run.

One recent file stealer sample we analyzed (SHA256: f211e0eb49990edbb5de2bcf2f573ea6a0b6f3549e772fd16bf7cc214d924824) was found to be a .NET binary that had been obfuscated to make analysis more difficult. The first thing that jumps out when reviewing these files are their sizes. This particular file clocks in at over 136 MB in size, but we observed files going all the way up to 200 MB and beyond. It is possible that this is an attempt to circumvent automated sandbox analysis, which usually avoids scanning such large files. It may also simply be a byproduct of the obfuscation tools being used. Whatever the reason for the large file size, it comes at a price to the attacker, as executables of this size stick out upon review. Transmitting a file this large to a victim becomes a much more challenging task.

The obfuscation within this sample is relatively simple and mainly relies upon defining arrays and concatenating strings of single characters in high volume over hundreds of lines to try to hide the construction of the actual string within the noise.
![The obfuscation within the Gamaredon file stealer sample we analyzed is relatively simple and mainly relies upon defining arrays and concatenating strings of single characters in high volume over hundreds of lines to try to hide the construction of the actual string within the noise, as shown in the example here.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image-7.png) Figure 8. Building the string "IconsCache.db" in the "text" variable.

It begins by checking for the existence of the Mutex Global\\lCHBaUZcohRgQcOfdIFaf, which, if present, implies the malware is already running and will cause the file stealer to exit. Next, it will create the folder C:\\Users\\%USER%\\AppData\\Local\\TEMP\\ModeAuto\\icons, wherein screenshots that are taken every minute will be stored and then transmitted to the C2 server with the name format YYYY-MM-DD-HH-MM.jpg.

To identify the IP address of the C2 server, the file stealer will generate a random string of alphanumeric characters between eight and 23 characters long, such as 9lGo990cNmjxzWrDykSJbV.jolotras\[.\]ru.

As mentioned previously, once the file stealer retrieves the IP address for this domain, it will no longer use the domain name. Instead, all communications will be direct with the IP address.

During execution, it will search all fixed and network drives attached to the computer for the following extensions:

.doc  
.docx  
.xls  
.rtf  
.odt  
.txt  
.jpg  
.pdf  
.ps1

When it has a list of files on the system, it begins to create a string for each that contains the path of the file, the size of the file and the last time the file was written to, similar to the example below:

C:\\cygwin\\usr\\share\\doc\\bzip2\\manual.pdf2569055/21/2011 3:17:02 PM

The file stealer takes this string and generates an MD5 hash of it, resulting in the following output for this example:

FB-17-F1-34-F4-22-9B-B4-49-0F-6E-3E-45-E3-C9-FA

Next, it removes the hyphens from the hash and converts all uppercase letters to lowercase. These MD5 hashes are then saved into the file C:\\Users\\%USER%\\AppData\\Local\\IconsCache.db. The naming of this file is another attempt to hide in plain sight next to the legitimate IconCache.db.
![The contents of "IconsCache.db," a database used by the Gamaredon file stealer malware to track unique files.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/02/word-image-8.png) Figure 9. IconsCache.db contents.

The malware uses this database to track unique files.

The malware will then generate a URL path with alphanumeric characters for its C2 communication, using the DNS-IP technique illustrated previously with the moolin\[.\]ru domain example:

https://194.67.109\[.\]164/zB6OZj6F0zYfSQ

Below is the full list of domains currently resolving to cluster 2 IP addresses:

|---------------------|----------------|
| **Domain**          | **Registered** |
| jolotras\[.\]ru     | 12/16/2021     |
| moolin\[.\]ru       | 10/11/2021     |
| bokuwai\[.\]ru      | 9/2/2021       |
| naniga\[.\]ru       | 9/2/2021       |
| nonimak\[.\]ru      | 9/2/2021       |
| bilargo\[.\]ru      | 7/23/2021      |
| krashand\[.\]ru     | 6/17/2021      |
| firtabo\[.\]ru      | 5/28/2021      |
| gorigan\[.\]ru      | 5/25/2021      |
| firasto\[.\]ru      | 5/21/2021      |
| myces\[.\]ru        | 2/24/2021      |
| teroba\[.\]ru       | 2/24/2021      |
| bacilluse\[.\]ru    | 2/15/2021      |
| circulas\[.\]ru     | 2/15/2021      |
| megatos\[.\]ru      | 2/15/2021      |
| phymateus\[.\]ru    | 2/15/2021      |
| cerambycidae\[.\]ru | 1/22/2021      |
| coleopteras\[.\]ru  | 1/22/2021      |
| danainae\[.\]ru     | 1/22/2021      |

*Table* *7* *. All cluster 2 domains.*

## Pteranodon (Cluster 3)

The single remaining IP address related to the SSL certificate was not related to either cluster 1 or cluster 2, and instead led us to a third, distinct cluster of domains.

This final cluster appears to serve as the C2 infrastructure for a custom remote administration tool called Pteranodon. Gamaredon has used, maintained and updated development of this code for years. Its code contains anti-detection functions specifically designed to identify sandbox environments in order to thwart antivirus detection attempts. It is capable of downloading and executing files, capturing screenshots and executing arbitrary commands on compromised systems.

Over the last three months, we have identified 33 samples of Pteranodon. These samples are commonly named 7ZSfxMod\_x86.exe. Pivoting across this cluster, we identified the following C2 infrastructure:

|------------------|----------------|
| **Domain**       | **Registered** |
| takak\[.\]ru     | 9/18/2021      |
| rimien\[.\]ru    | 9/18/2021      |
| maizuko\[.\]ru   | 9/2/2021       |
| iruto\[.\]ru     | 9/2/2021       |
| gloritapa\[.\]ru | 8/5/2021       |
| gortisir\[.\]ru  | 8/5/2021       |
| gortomalo\[.\]ru | 8/5/2021       |
| langosta\[.\]ru  | 6/25/2021      |
| malgaloda\[.\]ru | 6/8/2021       |

*Table 8. Cluster 3 domains.*

We again observe domain reputation aging, as seen in cluster 2.

An interesting naming pattern is seen in cluster 3 -- also seen in some cluster 1 host and subdomain names. We see these actors using English words, seemingly grouped by the first two or three letters. For example:

deep-rooted.gloritapa\[.\]ru  
deep-sinking.gloritapa\[.\]ru  
deepwaterman.gloritapa\[.\]ru  
deepnesses.gloritapa\[.\]ru  
deep-lunged.gloritapa\[.\]ru  
deerfood.gortomalo\[.\]ru  
deerbrook.gortomalo\[.\]ru  
despite.gortisir\[.\]ru  
des.gortisir\[.\]ru  
desire.gortisir\[.\]ru

This pattern differs from those of cluster 2, but has been observed on some cluster 1 (dropper) domains, for example:

alley81.salts.kolorato\[.\]ru  
allied.striman\[.\]ru  
allowance.hazari\[.\]ru  
allowance.telefar\[.\]ru  
ally.midiatr\[.\]ru  
allocate54.previously.bilorotka\[.\]ru  
alluded6.perfect.bilorotka\[.\]ru  
already67.perfection.zanulor\[.\]ru  
already8.perfection.zanulor\[.\]ru

This pattern is even carried into HTTP POSTs, files and directories created by associated samples:

Example 1:

SHA256: 74cb6c1c644972298471bff286c310e48f6b35c88b5908dbddfa163c85debdee

deerflys.gortomalo\[.\]ru

C:\\Windows\\System32\\schtasks.exe /CREATE /sc minute /mo 11 /tn "deepmost" /tr "wscript.exe "C:\\Users\\Public\\\\deep-naked\\deepmost.fly" counteract /create //b /criminal //e:VBScript /cracker counteract " /F

POST /index.eef/deep-water613

Example 2:

SHA256: ffb6d57d789d418ff1beb56111cc167276402a0059872236fa4d46bdfe1c0a13

deer-neck.gortomalo\[.\]ru

"C:\\Windows\\System32\\schtasks.exe" /CREATE /sc minute /mo 13 /tn "deep-worn" /tr "wscript.exe "C:\\Users\\Public\\\\deerberry\\deep-worn.tmp" crumb /cupboard //b /cripple //e:VBScript /curse crumb " /F

POST /cache.jar/deerkill523

Because we only see this with some domains, this may be a technique employed by a small group of actors or teams. It suggests a possible link between the cluster 3 samples and those from cluster 1 employing a similar naming system. In contrast, we do not observe cluster 2's large-number or random-string naming technique employed in any cluster 1 domains.

## Conclusion

Gamaredon has been targeting Ukrainian victims for almost a decade. As international tensions surrounding Ukraine remain unresolved, Gamaredon's operations are likely to continue to focus on Russian interests in the region. This blog serves to highlight the importance of research into adversary infrastructure and malware, as well as community collaboration, in order to detect and defend against nation-state cyberthreats. While we have mapped out three large clusters of currently active Gamaredon infrastructure, we believe there is more that remains undiscovered. Unit 42 remains vigilant in monitoring the evolving situation in Ukraine and continues to actively hunt for indicators to put protections in place to defend our customers anywhere in the world. We encourage all organizations to leverage this research to hunt for and defend against this threat.

### Protections and Mitigations

The best defense against this evolving threat group is a security posture that favors prevention. We recommend that organizations implement the following:

* Search network and endpoint logs for any evidence of the indicators of compromise associated with this threat group.
* Ensure cybersecurity solutions are effectively blocking against the active infrastructure IoCs identified above.
* Implement a DNS security solution in order to detect and mitigate DNS requests for known C2 infrastructure.
* Apply additional scrutiny to all network traffic communicating with AS 197695 (Reg\[.\]ru).
* If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call North America Toll-Free: 866.486.4842 (866.4.UNIT42), EMEA: +31.20.299.3130, APAC: +65.6983.8730, or Japan: +81.50.1790.0200.

For Palo Alto Networks customers, our products and services provide the following coverage associated with this campaign:

[Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) protects endpoints from the malware techniques described in this blog.

[WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) cloud-based threat analysis service accurately identifies the malware described in this blog as malicious.

[Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [DNS Security](https://www.paloaltonetworks.com/network-security/dns-security) identify all phishing and malware domains associated with this group as malicious.

Users of [AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus) contextual threat intelligence service can view malware associated with these attacks using the [Gamaredon Group tag](https://autofocus.paloaltonetworks.com/#/tag/Unit42.GamaredonGroup).

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

A list of the domains, IP addresses and malware hashes is available on the [Unit 42 GitHub](https://github.com/pan-unit42/iocs/blob/master/Gamaredon/Gamaredon_IoCs_JAN2022.txt).

[Additional IoCs](https://github.com/pan-unit42/iocs/blob/master/Gamaredon/2022_02_Gamaredon_UPDATE.txt) shared in a Feb. 16 update to this report are also available.

On June 22, we shared [additional Gamaredon IoCs](https://github.com/pan-unit42/iocs/blob/master/Gamaredon/2202_06_Gamaredon_IoC_UPDATE.txt).

## Additional Resources

[The Gamaredon Group Toolset Evolution](https://unit42.paloaltonetworks.com/unit-42-title-gamaredon-group-toolset-evolution/) -- Unit 42, Palo Alto Networks  
[Threat Brief: Ongoing Russia and Ukraine Cyber Conflict](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/) -- Unit 42, Palo Alto Networks  
[Technical Report on Armageddon / Gamaredon](https://ssu.gov.ua/uploads/files/DKIB/%D0%A2%D0%B5%D1%85%D0%BD%D1%96%D1%87%D0%BD%D0%B8%D0%B9%20%D0%B7%D0%B2%D1%96%D1%82%20%D0%B4%D1%96%D1%8F%D0%BB%D1%8C%D0%BD%D0%BE%D1%81%D1%82%D1%96%20%D0%90%D1%80%D0%BC%D0%B0%D0%B3%D0%B5%D0%B4%D0%BE%D0%BD.pdf) -- Security Service of Ukraine  
[Tale of Gamaredon Infection](https://www.ria.ee/sites/default/files/content-editors/kuberturve/tale_of_gamaredon_infection.pdf) -- CERT-EE / Estonian Information System Authority

*Updated November 30, 2022, at 11:25 a.m. PT.*
Back to top

### Tags

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")
* [Gamaredon](https://unit42.paloaltonetworks.com/tag/gamaredon/ "Gamaredon")
* [Primitive bear](https://unit42.paloaltonetworks.com/tag/primitive-bear/ "primitive bear")
* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")
* [Trident Ursa](https://unit42.paloaltonetworks.com/tag/trident-ursa/ "Trident Ursa")
* [Ukraine](https://unit42.paloaltonetworks.com/tag/ukraine/ "Ukraine")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Assessment: BlackCat Ransomware](https://unit42.paloaltonetworks.com/blackcat-ransomware/ "Threat Assessment: BlackCat Ransomware")

### Table of Contents

* 

### Related Articles

* [Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns](https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/ "article - table of contents")
* [Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "article - table of contents")
* [Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia](https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
