Also known as: Awaken Likho, APT28, Fancy Bear, Mango Sandstorm, Static Kitten, TA450, PseudoGamaredon, Head Mare, Bloody Wolf, SkyCloak, Bearlyfy, laboo.boo, Librarian Ghouls, Librarian Likho, Rezet, Lone Wolf, Moonshine Trickster, Clubfoot Wolf, Void Arachne, Watch Wolf, Ratopak Spider, UAC-0008, UAC-0001, Forest Blizzard, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, PhaseShifters, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, Pawn Storm, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, APT37, Earth Preta, HoneyMyte, Twill Typhoon, MuddyRot, UAC-0063, Parisite, Pioneer Kitten, UNC757
GamaCopy operates as part of a broader Russian-linked network that replicates tactics traditionally associated with groups such as Gamaredon. Its campaigns combine automated spear‑phishing vectors—mostly phishing emails bearing realistic military or government subject lines—with malicious attachments crafted in Smart Install Maker, PDF documents exploiting CVE‑2026‑21509, and password‑protected RAR archives containing remote‑access utilities like AnyDesk. Once a target system is compromised, the group deploys a PowerShell‑based backdoor (often termed PhantomHeart) that uses HTTP C2 channels and SSH tunnelling to move laterally. Persistence techniques include hijacking legitimate scheduled tasks and COM objects while obfuscating process windows to remain invisible in system monitors. GamaCopy also disables host‑side defense tools—including Windows Defender—through dedicated utilities, employs steganography to embed payloads in image files, and relies on cloud services such as Filen.io for data exfiltration. Additionally, the campaign sometimes incorporates Mirai‑style IoT malware to piggyback on compromised devices within the victim network. The actor’s toolset spans a range of openly available utilities: AnyDesk Remote Host executable, NetSupport, DynoWiper components such as BLINDINGCAN, and the Rust‑based backdoor character called CHAR. By blending these familiar tools with custom modules, GamaCopy increases its operational resilience against sandboxing and signature‑based detection. Overall, the group demonstrates a sophisticated blend of social engineering, supply‑chain compromise via legitimate software mimics, advanced persistence mechanisms, and covert exfiltration tactics—underscoring its commitment to long‑term espionage missions across diversified industries and geographies.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GamaCopy is a moderately sophisticated, state‑aligned threat actor that emerged in 2023 but has been active since 2021. It leverages a blend of custom malware, open‑source tools, and social engineering—particularly spear‑phishing with malicious Office macros—to infiltrate a wide spectrum of sectors across the globe. The group focuses on espionage against governmental, defense, critical infrastructure, and commercial targets, often using C2 over port 443 and exfiltration via SMTP to evade detection.
Goals & Targeting
GamaCopy’s strategic objective is to acquire sensitive technical and political information from high‑value targets in state, defense, critical infrastructure, and commercial sectors worldwide. By using culturally resonant phishing narratives—often framed as legitimate military communication—it aims to bypass users’ scrutiny while building footholds that provide continuous intelligence feeds via Remote Desktop tools and covert exfiltration channels. The actor prioritizes geographical breadth, targeting countries across Europe, Asia, the Americas, and the Middle East, with a particular focus on Russia’s domestic infrastructure and allied partners. The organization exhibits opportunistic expansion, incorporating publicly available exploits (e.g., TrueConf CVEs) whenever they become available to increase infection rates while maintaining stealth through dynamic server‑side evasion logic. Its ultimate intent is to sustain persistent presence and gather actionable data for political or economic espionage activities tied to the host nation’s strategic goals.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GamaCopy’s operations have been documented intermittently since 2021, with a surge in activity during the Russia-Ukraine conflict. The actor deploys daily spear‑phishing campaigns that mix legitimate imagery, military‑themed content, and malicious attachments; once executed, the malware can create multiple persistence pillars (scheduled tasks, COM hijack) while remaining hidden from standard endpoint defenses. The group exhibits a rapid deployment cadence—often delivering payloads within hours of credential compromise—and uses geographically tailored server‑side evasion to limit detection outside target nations. Victims span a wide range of industries: government ministries, defense contractors, critical infrastructure utilities, educational institutions, telecom operators, and commercial enterprises in sectors such as finance, energy, aeronautics, healthcare, and manufacturing. While the actor leverages both open‑source tools (AnyDesk, NetSupport) and custom code, there is evidence of destructive intentions via wiper functionality aimed at user profile directories—suggestive of a broader sabotage capability. Exfiltration primarily occurs over SMTP, sometimes masked within legitimate cloud storage traffic. Overall, GamaCopy demonstrates an adaptive, multi‑vector approach with both stealth and impact strategies, making it a persistent threat to global cyber sovereignty.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available evidence originates from multiple analytical reports and IOC repositories, giving a moderate confidence level in the core TTPs and toolset of GamaCopy. However, alias mapping remains partially speculative, as some name overlaps with unrelated groups; the exact attribution timeline is uncertain beyond 2021–2023. Key data gaps include precise first/last seen dates, comprehensive evidence linking all operational stages to a single actor, and deeper insights into internal command structures or funding sources.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
55
Tools
0
Campaigns
41
IOCs
0
Observed Data
7
Tactics