One dossier per actor with an assigned Malwarebox ID. Open a dossier for the profile, our analyses and the linked IIM Chains. The sequence at the left edge is the index: eight assigned, two reserved.
Gamaredon operates at a tempo that makes infrastructure the most reliable pivot: domains rotate faster than payloads change. We track the actor through dynamic DNS clusters and geofenced delivery, which restricts second-stage payloads to Ukrainian egress ranges. Each rotation window is documented with the Kraken query used to detect it, so the method is reproducible against later rotations.
IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA…
IIM chain for the November 2025 Gamaredon zero-click delivery path: a Ukraine-themed RAR archive abuses CVE-2025-6218/CVE-2025-8088 style archive delivery to place an HTA in the Windows Startup folder. The HTA/loader reaches DynDNS-backed delivery…
A single campaign entry, kept because the geofencing behaviour is instructive: the delivery filter is narrow enough that the allowed ranges themselves describe the target set. The analysis reconstructs the filter from collected samples and shows how the same signal can be queried across unrelated actors.
The interesting artefact here is not the malware but the workshop around it. Compiler fingerprints, path fragments and a recurring build identity ("Jacob") link samples that share no network infrastructure. Telegram bot naming follows a scheme regular enough to enumerate, which gives an early-warning signal ahead of campaign delivery.
Delivery hides the payload in alternate data streams of an archive, which survives most inspection paths that only read the primary stream. The follow-up tracks how the loader changed after the technique was published, which is the more useful half: it shows what the actor kept when the cheap part stopped working.
Ukraine-focused chain reconstructed from submitted artifacts and static analysis. The archive container itself was not submitted, so archive-level hash and original email metadata remain unavailable. The member names and dropped artifacts are consistent with…
Two analyses covering one shift in tradecraft. The first documents a OneDrive-hosted sideload chain ending in Remcos. The second covers the move to signed network components, which quietly retires the detection most defenders were relying on and forces the pivot back onto behaviour.
Observed UAC-0184 chain from gated HTA and ZIP delivery into Plane9-based sideloading, encoded local blobs, pseudo-PNG IDAT staging, LZNT1 unpacking and a signed VSLauncher / PassMark network-capable payload bundle. The internal controller or C2 element…
Two designations are tracked under one Malwarebox ID because the sample overlap is not yet separable. Delivery targets the operator workstation rather than the aircraft: trojanised configuration and firmware tooling distributed inside operator communities.
Campaign chain for a Ukraine-focused lure targeting FPV/UAV-related audiences. The flow starts with a humanitarian-aid themed archive/LNK and HTA delivery layer on ukrvarta.online, moves through external JavaScript and updater.txt payload staging, persists as…
The most self-built toolset in the registry. Each implant carries its own client certificate, so mutual TLS doubles as an access-control list and sinkholing needs the private key. The stager reads tasking from a Telegram dead drop and Vidar v2 arrives over a REALITY transport that mimics benign TLS. Tracked after publication by Zscaler ThreatLabz and the Belgian CCB.
CHM remains in use because it survives filtering that blocks macros and script attachments outright. The analysis walks the compiled help file end to end, from the embedded shortcut object to the PowerShell recon stage and gives the extraction steps needed to compare CHM samples at volume.
ENKI-attributed Kimsuky lane. Fake Webex page based on a legitimate meeting schedule downloads an ALZip archive containing fix-camera.jse, which drops meeting.html and mTSTCv8.mdxm/loadDll.dll. The downloader retrieves engine.dat/spyInster.dll, which installs…
Pick what you want to hear about. One address, no cadence you did not ask for.