March 31, 2025 By Pierluigi Paganini
Russia-linked Gamaredon targets Ukraine with a phishing campaign using troop-related lures to deploy the Remcos RAT via PowerShell downloader.
Talos researchers warn that Russia-linked APT group Gamaredon (a.k.a. Armageddon, Primitive Bear, ACTINIUM, Callisto) targets Ukraine with a phishing campaign. The cyberespionage group is behind a long series of spear-phishing attacks targeting Ukrainian entities, and organizations related to Ukrainian affairs. The APT group has been launching cyber-espionage campaigns against Ukraine since at least 2014.
The threat actor is using troop-related lures to deploy the Remcos RAT via PowerShell downloader.