GamaCopy — APT Profile
GamaCopy mimics the TTPs of Gamaredon to launch cyberattacks against Russia’s defense and critical infrastructure sectors, and was first discovered in June 2023. The organization has been active since at least August 2021 and primarily uses Russian-language bait documents related to military facilities. Analysis of attack samples shows considerable overlap in code structure and tactics, including the use of 7z-SFX documentation to install UltraVNC and connecting via port 443. GamaCopy employs open-source tools to obfuscate its activities while targeting sensitive information in the context of the Russia-Ukraine conflict.Also tracked as
Core Werewolf, Awaken Likho, PseudoGamaredon
Tools & malware
- 7z SFX (self-extracting archive) Loader
- AutoIt loader/dropper Loader
- MeshAgent / MeshCentral Tool
- Obfuscated batch script (EnableDelayedExpansion) Loader
- UltraVNC Tool
Vendor research
- Love and hate under war: The GamaCopy organization, which imitates the Russian Gamaredon, uses military-related bait to launch attacks on Russia Knownsec 404 Team
- GamaCopy Mimics Gamaredon Tactics in Cyber Espionage Targeting Russian Entities The Hacker News
- GamaCopy targets Russia mimicking Russia-linked Gamaredon APT Security Affairs
- Awaken Likho is awake: new techniques of an APT group Kaspersky (Securelist)
- Hackers imitate Kremlin-linked group to target Russian entities Recorded Future (The Record)
Countries linked to this actor
- Russia targets