In early 2023, the Gamaredon group, a cybercrime group with ties to Russian government-backed attackers, struck again with new attacks targeting government agencies across Europe. The group has already been linked to numerous malware campaigns and has expanded its capabilities over the years, making them a major threat to organizations and consumers alike.
Gamaredon has now launched attacks using a combination of Delphi, Hexat, and VBScript malware families as well as phishing tactics. According to security researchers, this new attack campaign has been spotted in countries including Italy, Germany, and Ukraine, but the attackers are believed to have infiltrated networks in other locations too.
The attackers are targeting government agencies, the intelligence community, and infrastructure networks. Gamaredon's goal is to gain access to confidential data, including information stored in government databases, as well as financial and other sensitive data.
Gamaredon is using a range of techniques to achieve its goals, including exploiting vulnerabilities, hijacking networks, and sending malicious code to targets. The group is also leveraging a range of public exploit portals, which it uses to launch its campaigns.
The group's activities have been tracked by a variety of security teams, including those from Trend Micro, Cybereason, and F-Secure. The security researchers have noted that Gamaredon is actively expanding its operations and aims to target additional government agencies and critical infrastructure networks.
Organizations should ensure that their networks and systems are regularly updated, as Gamaredon and other attackers may use known vulnerabilities to gain access to sensitive data. Additionally, implementing strong authentication and encryption, as well as monitoring user activity, can all help prevent a successful attack.
Gamaredon group's persistent and targeted attacks put data and user privacy at risk, which underscores the importance of implementing effective security measures. Government agencies, organizations, and consumers should take necessary steps to protect themselves from Gamaredon's cyberthreats.
This Cyber News was published on thehackernews.com. Publication date: Mon, 23 Jan 2023 18:57:29 +0000