Also known as: Vengeful Wolf, room155, APT28, Fancy Bear, Storm-0978, Tropical Scorpius, tracked as, Paper Werewolf, Rare Werewolf, Central Asia, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Smoke Sandstorm, TA455, Yellow Liderc, Tortoiseshell, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin, Blue Echidna, UNC2596, GOFFEE, Fluffy Wolf, Imperial Kitten, LuoYu, CASCADE PANDA, Qilin, file transfer tools, Sandworm, CVE-2025-23006, Samurai Panda, PLA Navy, APT4, Wisp Team
DarkGaboon is an APT with the primary objective of financial gain. Its campaign record shows sophisticated use of spear‑phishing emails that deliver weaponized documents (DOCX files exploiting legacy CVEs like CVE-2017-0199 and CVE-2017-11882) or malicious archives containing obfuscated PowerShell loaders, HTA executables, or backdoor binaries such as DarkGate, BrockenDoor, and Remcos. The group enhances its threat envelope by disguising malware with homoglyph filenames, double‑extension patterns (e.g., .pdf.scr), fake X.509 certificates, and icons mimicking legitimate Office or PDF files while protecting payloads with Themida or .NET Reactor.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DarkGaboon is a financially motivated APT that has been targeting Russian organizations since mid‑2023 primarily through spear‑phishing campaigns utilizing weaponized documents and malicious archives. The group employs a sophisticated blend of remote access trojans, custom backdoors, and ransomware (LockBit 3.0, Babuk) while leveraging advanced evasion techniques such as homograph file names, dynamic DNS C2 domains, and in‑memory PowerShell loaders. DarkGaboon’s operations demonstrate disciplined tool updates and strong operational security practices, making it a significant threat to critical national infrastructure sectors.
Goals & Targeting
DarkGaboon concentrates on high‑value targets across a broad geostrategic spectrum, prioritizing Russian and allied entities in finance, defense, government, energy, transportation, manufacturing, telecommunications, critical infrastructure, healthcare, and technology. Its operational tempo is sustained with periodic refreshes of its toolset—over 360 unique binaries have been catalogued—and it consistently demonstrates an ability to pivot across industries by exploiting legacy vulnerabilities (e.g., CVE‑2024‑11182 in MDaemon) and leveraging stolen credentials for lateral movement via RDP, SSH, or VPN connections.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DarkGaboon’s operations exhibit a pattern of regular penetration attempts across a diversified industry portfolio, with a clear focus on Russian entities but extending to other strategic regions such as the US, China, Ukraine, and the Middle East. The actor routinely updates its toolchain, maintaining a library of more than 360 distinct binaries that are introduced through polished spear‑phishing campaigns. Notably, DarkGaboon has escalated from data exfiltration to ransomware deployment (LockBit 3.0, Babuk), consistently targeting financial and critical infrastructure sectors while employing defensive evasion techniques, such as dynamic DNS C2 clusters and homograph file names, to avoid detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple independent intelligence reports and publicly available malware samples, providing moderate confidence in the actor’s TTPs, toolset, and sector focus. However, gaps remain concerning precise attribution timelines, exact geographic origins beyond Russia, and full scope of their financial impact. Further corroboration from internal forensic data or additional external sources would strengthen confidence levels.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
63
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics