- Symantec says it found gammasteel on units belonging to a military operation in Ukraine
- Gammasteel is an infoTeals built by Russian Cyber-Outfit Gamaredon
- Gamaredon is one of many groups on gravel payroll
A “military mission in a Western country” located in Ukraine was the target of a Russian cyber-espionage attack, according to cybersecurity scientists Symantec, who said they identified an attack that started in February 2025 and probably continued for several weeks.
The researchers claim that the attack started with an infected removable drive containing a malicious .LNK file that triggered an infection chain which resulted in the implementation of gamma steel.
GammaSteel is an infoTealer -Malware capable of exfiltering documents in different formats such as .docx, .pdf, .xls, .txt and more. It was probably built and deployed by a Russian state -sponsored threat actor known as Gamaredon (or Shuckworm).
Infected removable drives
In addition to stealing files, it can also take screenshots of the infected device and collect important information about things like installed antivirus tools, running processes and more.
Finally, the tool establishes Persistence on the compromised final points via a new Windows Registry Post. The researchers said the threat actors changed their tactics a little to better hide the payload.
Symantec did not say if the military mission was compromised, or what kind of information – if any – was stolen in the attack. It is safe to assume that the attack is part of a wider cyber war effort since Russia invaded Ukraine more than three years ago.
Russian aggression has shown how much warning changed and became digital. The digital world became a whole front with Russian cyber infantry targeting communication satellites, the government’s endpoints, electrical stations and more.
The Ukrainians responded by hacking Russian TV and radio to send out anti-war messages, manipulated a taxi app to send dozens of cars to a single place in Moscow and leaked gigabytes of data from Russian devices, including the private military Wagner Group.
Gamaredon is only one of many groups actively involved in the war, next to Conti or Sandworm. Everyone is apparently part of GRU, Russia’s military intelligence unit.
Via Bleeping computer