Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DarkGaboon

Also known as: Vengeful Wolf, room155, APT28, Fancy Bear, Storm-0978, Tropical Scorpius, tracked as, Paper Werewolf, Rare Werewolf, Central Asia, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Smoke Sandstorm, TA455, Yellow Liderc, Tortoiseshell, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin, Blue Echidna, UNC2596, GOFFEE, Fluffy Wolf, Imperial Kitten, LuoYu, CASCADE PANDA, Qilin, file transfer tools, Sandworm, CVE-2025-23006, Samurai Panda, PLA Navy, APT4, Wisp Team

Description

DarkGaboon is an APT with the primary objective of financial gain. Its campaign record shows sophisticated use of spear‑phishing emails that deliver weaponized documents (DOCX files exploiting legacy CVEs like CVE-2017-0199 and CVE-2017-11882) or malicious archives containing obfuscated PowerShell loaders, HTA executables, or backdoor binaries such as DarkGate, BrockenDoor, and Remcos. The group enhances its threat envelope by disguising malware with homoglyph filenames, double‑extension patterns (e.g., .pdf.scr), fake X.509 certificates, and icons mimicking legitimate Office or PDF files while protecting payloads with Themida or .NET Reactor.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Energy
Transportation
Manufacturing
Telecommunications
Critical infrastructure
Education
Retail
Aerospace
Media
Construction
Healthcare
Utilities
Food agriculture
Aviation
Oil gas
Pharmaceutical
Chemical
Maritime
Nuclear
Non profit
Information technology
Entertainment
Gaming

Targeted Countries / Regions

RU
US
CN
UA
TW
IL
KR
CA
TR
IN
BR
AE
BY
IR
JP
VN
SA
AU
EG
FR
GB
DE
MX

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 13 minutes ago

Executive Summary

DarkGaboon is a financially motivated APT that has been targeting Russian organizations since mid‑2023 primarily through spear‑phishing campaigns utilizing weaponized documents and malicious archives. The group employs a sophisticated blend of remote access trojans, custom backdoors, and ransomware (LockBit 3.0, Babuk) while leveraging advanced evasion techniques such as homograph file names, dynamic DNS C2 domains, and in‑memory PowerShell loaders. DarkGaboon’s operations demonstrate disciplined tool updates and strong operational security practices, making it a significant threat to critical national infrastructure sectors.

Goals & Targeting

DarkGaboon concentrates on high‑value targets across a broad geostrategic spectrum, prioritizing Russian and allied entities in finance, defense, government, energy, transportation, manufacturing, telecommunications, critical infrastructure, healthcare, and technology. Its operational tempo is sustained with periodic refreshes of its toolset—over 360 unique binaries have been catalogued—and it consistently demonstrates an ability to pivot across industries by exploiting legacy vulnerabilities (e.g., CVE‑2024‑11182 in MDaemon) and leveraging stolen credentials for lateral movement via RDP, SSH, or VPN connections.

Enhanced Description

Key Capabilities

  • spear phishing attacks
  • use of legitimate software in execution
  • deployment of remote access trojans
  • data theft and destruction
  • encryption of victim infrastructure using LockBit 3.0 ransomware
  • use of fake X.509 certificates and homoglyph file names to masquerade malware
  • deployment of double‑extension files (e.g., .pdf.scr, .xlsx.scr) with disguised icons
  • protection of binaries with Themida and .NET Reactor
  • obfuscated .NET megadropper that extracts multiple payloads
  • dynamic DNS domains organized in two non‑overlapping clusters
  • phishing attachments delivering backdoors such as DarkGate, BrockenDoor, and Remcos
  • living‑off‑the‑Land tactics via PowerShell and WMI
  • persistence through creation of scheduled tasks on Windows
  • privilege escalation using compromised employee accounts and remote protocols (RDP, SSH, VPN)
  • backup destruction with the SDelete utility
  • deployment of Babuk ransomware for data encryption and ransom demands
  • exploitation of CVE‑2024‑11182 XSS vulnerability in MDaemon Email Server
  • Microsoft Office CVE‑2012‑0158 exploitation
  • Ivanti EPMM CVE‑2025‑44277/88 exploitation
  • phishing emails with malicious archive payloads (ZIP containing LNK and HTA loaders)
  • weaponized DOCX files exploiting legacy CVEs CVE-2017-0199 and CVE-2017-11882
  • obfuscated PowerShell loader that decrypts shellcode in memory before execution
  • deployment of Cobalt Strike beacons using a custom malleable profile for C2 evasion
  • multiple infection chains and decoys targeting finance/legal departments

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Impact
Command and Control

ATT&CK Techniques

T1566
T1059.001
T1047
T1566.001
T1027
T1036
T1053.006
T1021
T1485
T1490
T1203
T1190
T1566.002
T1055

Software / Tooling

.NET Reactor
Auto-Color Linux backdoor
Cobalt Strike
DarkGate
Elise (Trensil)
Embe
FRP (Fast Reverse Proxy)
Havex RAT
More Eggs
MeshCentral Agent
Remcos
SDelete
.NET Reactor
BrokeDoor
Babuk
PowerShell
KrustyLoader
Sliver implants
SysBC
Plink
Ngrok
Themida

Campaigns & Victims

DarkGaboon’s operations exhibit a pattern of regular penetration attempts across a diversified industry portfolio, with a clear focus on Russian entities but extending to other strategic regions such as the US, China, Ukraine, and the Middle East. The actor routinely updates its toolchain, maintaining a library of more than 360 distinct binaries that are introduced through polished spear‑phishing campaigns. Notably, DarkGaboon has escalated from data exfiltration to ransomware deployment (LockBit 3.0, Babuk), consistently targeting financial and critical infrastructure sectors while employing defensive evasion techniques, such as dynamic DNS C2 clusters and homograph file names, to avoid detection.

IOC Patterns

  • fake X.509 certificates
  • homoglyph usage in executable names
  • email subjects and attachment titles with deceptive formatting
  • double extensions (.pdf.scr) in malicious files
  • icons mimicking MS Office or PDF for hidden malware
  • dynamic DNS domain clusters for command and control
  • spear‑phishing attachments dropping backdoors
  • WebDAV exploitation of CVE-2025-33053
  • stolen credentials accessing SSL VPN systems
  • publicly accessible web shells on victim servers
  • backdoors such as MeshCentral Agent and SystemBC installed
  • Biotime vulnerabilities CVE‑2023‑38950/51/52 for re-entry
  • spear‑phishing links via malicious URLs
  • ZIP archives containing LNK and HTA loaders
  • weaponized DOCX files exploiting CVE-2017-0199/CVE-2017-11882
  • obfuscated PowerShell scripts that decrypt shellcode in memory
  • custom Cobalt Strike malleable profile for C2 communication

Recommended Actions

  • Patch MDaemon Email Server to mitigate CVE‑2024‑11182 and update Ivanti EPMM for CVE‑2025‑44277/88. Apply all available security updates promptly.
  • Monitor dynamic DNS activity and block suspicious domain clusters using reputation services.
  • Implement file policy to detect and block double‑extension files or homoglyph filenames; enforce strict attachment handling controls.
  • Strengthen user awareness training against spear‑phishing; adopt DMARC, SPF, and DKIM email authentication mechanisms.
  • Configure endpoint detection to flag known backdoor families such as DarkGate, Remcos, BrockenDoor, and ransomware variants LockBit 3.0 and Babuk.
  • Enable logging and continuous monitoring of scheduled tasks to detect unauthorized persistence mechanisms.
  • Enforce multi‑factor authentication and least privilege on all user accounts; restrict remote service access (RDP/SSH/VPN) to approved devices only.
  • Protect backups by using immutable or off‑network storage, regularly audit integrity, and ensure backup copies are stored separately from production networks.
  • Patch CVE‑2025‑33053 as soon as possible; apply patches for CVEs‑2023‑38950/51/52.
  • Enforce multi‑factor authentication for VPN and critical systems.
  • Detect and remove unauthorized web shells and backdoor binaries.
  • Maintain regular vulnerability scanning and patch management.
  • Deploy email filtering and attachment sandboxing to block malicious archives and weaponized documents.
  • Apply security patches to address CVE‑2017‑0199 (Drupal) and CVE‑2017‑11882 (Office).
  • Detect and block obfuscated PowerShell activity using EDR solutions.
  • Monitor network traffic for Cobalt Strike beacon patterns, especially custom malleable profiles.

Suggested Tags

APT
Spearphishing
Remote Access Trojan (RAT)
Russian-targeted
PhantomCore
Head Mare
BO Team
Black Owl
Lifting Zmiy
Hoody Hyena
Billbug
Lotus Blossom
Lotus Panda
Bronze Elgin
LockBit 3.0
Babuk
DarkGate
BrockenDoor
Remcos
UNC5221
Lemon Sandstorm
Parisite
Pioneer Kitten
UNC757
Stealth Falcon
FruityArmor
SHADOW‑VOID‑042
Void Rabisu
RomCom
Financially Motivated
Russian B2B Targeting
Phishing with Malicious Attachments
Weaponized Document Exploit
Legacy CVE Exploitation
Obfuscated PowerShell Loader
In-Memory Shellcode Deployment
Custom Cobalt Strike Malleable Profile
DarkGaboon

Confidence Assessment

The analysis is based on multiple independent intelligence reports and publicly available malware samples, providing moderate confidence in the actor’s TTPs, toolset, and sector focus. However, gaps remain concerning precise attribution timelines, exact geographic origins beyond Russia, and full scope of their financial impact. Further corroboration from internal forensic data or additional external sources would strengthen confidence levels.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  3. risky.biz — Cited by web research for: CVE-2024-8963
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/js.more_eggs — Cited by AI analysis.

Intel Summary

14

Techniques

63

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
APT
Phishing
Backdoor / C2
ransomware
financial-motivations
Russian-speaking actors
banking-sector
Spearphishing
Remote Access Trojan (RAT)
Russian-targeted
PhantomCore
Head Mare
BO Team
Black Owl
Lifting Zmiy
Hoody Hyena
Billbug
Lotus Blossom
Lotus Panda
Bronze Elgin
LockBit 3.0
Babuk
DarkGate
BrockenDoor
Remcos
UNC5221
Lemon Sandstorm
Parisite
Pioneer Kitten
UNC757
Stealth Falcon
FruityArmor
SHADOW‑VOID‑042
Void Rabisu
RomCom
Financially Motivated
Russian B2B Targeting
Phishing with Malicious Attachments
Weaponized Document Exploit
Legacy CVE Exploitation
Obfuscated PowerShell Loader
In-Memory Shellcode Deployment
Custom Cobalt Strike Malleable Profile
DarkGaboon

Details

MITRE ID
APT4
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.