The Russia-linked espionage group Shuckworm, also known as Gamaredon or Armageddon, has launched a new wave of cyberattacks against entities in Ukraine, employing an updated variant of its infamous GammaSteel malware.
The campaign, observed during February and March 2025, demonstrates Shuckworm’s growing reliance on PowerShell-based tools, which enhance obfuscation capabilities and facilitate data exfiltration from victim networks.
Targeted Attack Chain Involving Removable Drives and Obfuscated Scripts
Shuckworm’s latest campaign began on February 26, 2025, with evidence pointing to an infected removable drive as the initial attack vector.
From there, a Windows Registry value under the UserAssist key was created, suggesting the use of a malicious LNK file to initiate the infection chain.
The group employed a multi-layered strategy involving obfuscated VBScript and PowerShell scripts stored in the registry likely to evade traditional detection mechanisms.
As part of this attack, two files NTUSER.DAT.TMContainer00000000000000000001.regtrans-ms and NTUSER.DAT.TMContainer00000000000000000002.regtrans-ms were crucial in executing the malware’s objectives.
The first file maintained constant communication with the command-and-control (C&C) infrastructure, leveraging legitimate services like Telegram, Teletype, and Cloudflare tunnels to obscure its activities.
The second file modified registry keys to hide files, and spread the infection to connected devices by creating malicious shortcut (.lnk) files.
GammaSteel Malware: Enhanced Exfiltration and Reconnaissance Features
The updated GammaSteel malware, now deployed as a PowerShell variant, underscores Shuckworm’s shift from VBScript-based tools to PowerShell scripts.
This transition grants the attackers additional flexibility in storing payloads in the registry and executing scripts via legitimate system tools.
GammaSteel’s capabilities have been expanded to include reconnaissance modules that collect sensitive system information, such as screen captures, running processes, disk configurations, and installed security software.
Shuckworm’s exfiltration methods have also become more sophisticated.
The malware targets specific file types documents, spreadsheets, presentations, PDFs, and others while avoiding common system directories.
Using PowerShell web requests or cURL with Tor proxies, the attackers ensure sensitive data is extracted stealthily.
GammaSteel even utilizes certutil.exe to generate MD5 hashes for exfiltrated files, indicating an advanced approach toward data authentication before transmission.
The campaign reveals Shuckworm’s growing reliance on decentralized and legitimate web services for resolving its C&C infrastructure.
Examples of C&C domains include telegra.ph, write.as, and servers hosted behind Cloudflare tunnels.
This tactic complicates attribution and detection efforts for defenders. Once operational, the malware registers itself in the Windows Run key for persistence, ensuring it executes upon system startup.
In one notable instance, Shuckworm launched PowerShell commands to download additional payloads from its C&C servers.
According to the Report, these payloads included reconnaissance scripts and further obfuscated malware stored in registry keys.
The attackers appear to have refined their payload-delivery process by splitting malicious functions across multiple registry values, making reverse engineering more challenging.
Defensive Measures and Mitigation
Organizations targeted by Shuckworm, especially those in Ukraine, must implement stringent security measures to protect against GammaSteel malware.
Endpoint solutions should be capable of monitoring registry changes and detecting obfuscated PowerShell scripts.
Restricting the use of removable drives and enforcing robust network segmentation are crucial preventive steps.
Additionally, threat intelligence teams should actively monitor indicators of compromise (IOCs) associated with Shuckworm’s infrastructure, including the specific domains and IPs flagged in recent investigations.
Symantec Endpoint products and other advanced solutions are recommended for detecting and neutralizing GammaSteel attacks.
This campaign serves as a reminder of the escalating cyber threat landscape in Eastern Europe, where espionage-driven attacks continue to target sensitive institutions and infrastructure.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates