Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GamaCopy

Also known as: Awaken Likho, APT28, Fancy Bear, Mango Sandstorm, Static Kitten, TA450, PseudoGamaredon, Head Mare, Bloody Wolf, SkyCloak, Bearlyfy, laboo.boo, Librarian Ghouls, Librarian Likho, Rezet, Lone Wolf, Moonshine Trickster, Clubfoot Wolf, Void Arachne, Watch Wolf, Ratopak Spider, UAC-0008, UAC-0001, Forest Blizzard, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, PhaseShifters, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, Pawn Storm, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, APT37, Earth Preta, HoneyMyte, Twill Typhoon, MuddyRot, UAC-0063, Parisite, Pioneer Kitten, UNC757

Description

GamaCopy operates as part of a broader Russian-linked network that replicates tactics traditionally associated with groups such as Gamaredon. Its campaigns combine automated spear‑phishing vectors—mostly phishing emails bearing realistic military or government subject lines—with malicious attachments crafted in Smart Install Maker, PDF documents exploiting CVE‑2026‑21509, and password‑protected RAR archives containing remote‑access utilities like AnyDesk. Once a target system is compromised, the group deploys a PowerShell‑based backdoor (often termed PhantomHeart) that uses HTTP C2 channels and SSH tunnelling to move laterally. Persistence techniques include hijacking legitimate scheduled tasks and COM objects while obfuscating process windows to remain invisible in system monitors. GamaCopy also disables host‑side defense tools—including Windows Defender—through dedicated utilities, employs steganography to embed payloads in image files, and relies on cloud services such as Filen.io for data exfiltration. Additionally, the campaign sometimes incorporates Mirai‑style IoT malware to piggyback on compromised devices within the victim network. The actor’s toolset spans a range of openly available utilities: AnyDesk Remote Host executable, NetSupport, DynoWiper components such as BLINDINGCAN, and the Rust‑based backdoor character called CHAR. By blending these familiar tools with custom modules, GamaCopy increases its operational resilience against sandboxing and signature‑based detection. Overall, the group demonstrates a sophisticated blend of social engineering, supply‑chain compromise via legitimate software mimics, advanced persistence mechanisms, and covert exfiltration tactics—underscoring its commitment to long‑term espionage missions across diversified industries and geographies.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Energy
Non profit
Telecommunications
Manufacturing
Education
Aerospace
Maritime
Transportation
Media
Healthcare
Critical infrastructure
Construction
Information technology
Think tank
Chemical
Mining
Pharmaceutical
Retail
Nuclear
Aviation
Utilities
Hospitality
Legal services
Entertainment
Oil gas

Targeted Countries / Regions

US
RU
CN
UA
GB
IN
DE
PL
JP
KR
SA
IR
KZ
PK
IL
TR
TW
CA
AE
FR
BR
AU
BY
VN
MX
RO
ES
NL
IT
SG
IQ
SY
KP
NG
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

GamaCopy is a moderately sophisticated, state‑aligned threat actor that emerged in 2023 but has been active since 2021. It leverages a blend of custom malware, open‑source tools, and social engineering—particularly spear‑phishing with malicious Office macros—to infiltrate a wide spectrum of sectors across the globe. The group focuses on espionage against governmental, defense, critical infrastructure, and commercial targets, often using C2 over port 443 and exfiltration via SMTP to evade detection.

Goals & Targeting

GamaCopy’s strategic objective is to acquire sensitive technical and political information from high‑value targets in state, defense, critical infrastructure, and commercial sectors worldwide. By using culturally resonant phishing narratives—often framed as legitimate military communication—it aims to bypass users’ scrutiny while building footholds that provide continuous intelligence feeds via Remote Desktop tools and covert exfiltration channels. The actor prioritizes geographical breadth, targeting countries across Europe, Asia, the Americas, and the Middle East, with a particular focus on Russia’s domestic infrastructure and allied partners. The organization exhibits opportunistic expansion, incorporating publicly available exploits (e.g., TrueConf CVEs) whenever they become available to increase infection rates while maintaining stealth through dynamic server‑side evasion logic. Its ultimate intent is to sustain persistent presence and gather actionable data for political or economic espionage activities tied to the host nation’s strategic goals.

Enhanced Description

Key Capabilities

  • custom malware development
  • PowerShell-based backdoor deployment
  • HTTP C2 communication with SSH tunneling
  • task scheduler persistence disguised as legitimate updater
  • exploitation of known vulnerabilities (TrueConf BDU:2025‑10114/10116)
  • phishing via malicious PDFs and video conference links
  • Java-based malicious downloaders
  • use of legitimate software (NetSupport) for malware delivery
  • incorporation of Mirai IoT malware
  • automated spear-phishing campaigns with malicious attachments
  • installer built with Smart Install Maker that drops multiple archive files
  • extraction and execution of payloads from password‑protected RAR archives
  • remote desktop access via AnyDesk host executable
  • disabling Windows Defender through dedicated utility
  • exfiltration of data over SMTP
  • hiding process windows to evade detection
  • password extraction from email clients
  • zero‑day exploitation of Microsoft MSHTML framework (CVE-2026-21509, CVE-2026-21513)
  • steganography to conceal payloads within Excel files and PNG images
  • establishing persistence via COM hijacking
  • loading proxy DLL that reconstructs payloads from steganographic images
  • abusing cloud storage services (Filen.io, MEGA.nz) for C2 communications and data exfiltration
  • deploying destructive wiper command deleting user profile directory files
  • leveraging spear-phishing with malicious VBA macros to deploy Rust backdoor binary
  • detecting installed security software on victim machines
  • creating Windows registry persistence keys via malicious PowerShell commands
  • downloading second-stage payloads using HTTP_VIP downloader (GhostFetch) and Rust backdoor (CHAR)
  • using malicious LNK shortcuts to execute PowerShell download scripts
  • uploading collected data using legitimate Rclone executable
  • employing hex‑encoded payload embedding within UserForm controls in VBA macros

MITRE ATT&CK Tactics

Resource Development
Execution
Persistence
Command and Control
Initial Access
Defense Evasion
Exfiltration

ATT&CK Techniques

T1587.001
T1059.001
T1071.001
T1090.005
T1053.005
T1566.001
T1059.003
T1105
T1041
T1497.001

Software / Tooling

BLINDINGCAN
DCSrv
PyDCrypt
PhantomHeart
PhantomProxyLite
PhantomPxPigeon
STRRAT (Strigoi Master)
NetSupport
Mirai IoT
Smart Install Maker
AnyDesk Remote Host Management EXE
Custom WinRAR
MiniDoor Outlook Macro Stealer
PixyNetLoader Covenant Grunt

Campaigns & Victims

GamaCopy’s operations have been documented intermittently since 2021, with a surge in activity during the Russia-Ukraine conflict. The actor deploys daily spear‑phishing campaigns that mix legitimate imagery, military‑themed content, and malicious attachments; once executed, the malware can create multiple persistence pillars (scheduled tasks, COM hijack) while remaining hidden from standard endpoint defenses. The group exhibits a rapid deployment cadence—often delivering payloads within hours of credential compromise—and uses geographically tailored server‑side evasion to limit detection outside target nations. Victims span a wide range of industries: government ministries, defense contractors, critical infrastructure utilities, educational institutions, telecom operators, and commercial enterprises in sectors such as finance, energy, aeronautics, healthcare, and manufacturing. While the actor leverages both open‑source tools (AnyDesk, NetSupport) and custom code, there is evidence of destructive intentions via wiper functionality aimed at user profile directories—suggestive of a broader sabotage capability. Exfiltration primarily occurs over SMTP, sometimes masked within legitimate cloud storage traffic. Overall, GamaCopy demonstrates an adaptive, multi‑vector approach with both stealth and impact strategies, making it a persistent threat to global cyber sovereignty.

IOC Patterns

  • DLL or PowerShell script files used as delivery payloads
  • Scheduled task entries named like legitimate update scripts in LiteManager directory
  • Malicious PDF attachments sent via phishing emails
  • Unsigned TrueConf client binaries replacing official ones
  • Domain-based distribution infrastructure for malware
  • Phishing email with malicious executable attachment
  • Office document exploiting CVE‑2026‑21509
  • Password‑protected RAR archive download from C2 address
  • Server‑side evasion responding only to specific geographic region and User‑Agent header

Recommended Actions

  • Monitor and block unusual PowerShell execution, especially from new tasks
  • Inspect and secure scheduled tasks; block unknown or disguised updates
  • Implement email filtering to detect and drop malicious PDFs and phishing links
  • Verify digital signatures of software updates; block unsigned executables
  • Patch systems against TrueConf vulnerabilities (BDU:2025-10114/10116)
  • Deploy application whitelisting to restrict execution of unknown installers
  • Patch the CVE‑2026‑21509 vulnerability on all affected systems immediately
  • Monitor for and block AnyDesk remote host management utilities
  • Enforce Windows Defender to remain enabled; detect any attempts to disable it
  • Detect and block SMTP‑based data exfiltration traffic
  • Identify anomalous process hiding or window removal behavior

Suggested Tags

Head Mare
Stan Ghouls
Bloody Wolf
PhantomHeart
PhantomPxPigeon
NetSupport
Mirai
PowerShell
Scheduled Task
Phishing
TrueConf Vulnerability
Spear‑phishing attachment
CVE-2026‑21509
Office exploit
Remote desktop abuse (AnyDesk)
Defender disable
SMTP exfiltration
Password extraction
Server‑side evasion

Confidence Assessment

The available evidence originates from multiple analytical reports and IOC repositories, giving a moderate confidence level in the core TTPs and toolset of GamaCopy. However, alias mapping remains partially speculative, as some name overlaps with unrelated groups; the exact attribution timeline is uncertain beyond 2021–2023. Key data gaps include precise first/last seen dates, comprehensive evidence linking all operational stages to a single actor, and deeper insights into internal command structures or funding sources.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Awaken Likho
  2. thehackernews.com — Cited by web research for: PseudoGamaredon
  3. attack.mitre.org — Cited by web research for: T1587.002
  4. misp-galaxy.org — Cited by web research for: Jackal
  5. brandefense.io — Cited by web research for: Dark
  6. thehackernews.com — Cited by web research for: LucidRook
  7. https://therecord.media/hacker-imitates-gamaredon-to-target-russia — Cited by AI analysis.
  8. https://malpedia.caad.fkie.fraunhofer.de/details/win.blindingcan — Cited by AI analysis.

Intel Summary

14

Techniques

55

Tools

0

Campaigns

41

IOCs

0

Observed Data

7

Tactics

Tags

Critical Infrastructure
Government Targeting
APT
Espionage
Geopolitical
Russian-speaking actors
Head Mare
Stan Ghouls
Bloody Wolf
PhantomHeart
PhantomPxPigeon
NetSupport
Mirai
PowerShell
Scheduled Task
Phishing
TrueConf Vulnerability
Spear‑phishing attachment
CVE-2026‑21509
Office exploit
Remote desktop abuse (AnyDesk)
Defender disable
SMTP exfiltration
Password extraction
Server‑side evasion

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.