Hi All
As of April 2024, IBM X-Force is tracking new waves of Russian state-sponsored Hive0051 (aka UAC-0010, Gamaredon) activity featuring new iterations of Gamma malware first observed in November 2023. These discoveries follow late October 2023 findings, detailing Hive0051’s use of a novel multi-channel method of rapidly rotating C2 infrastructure (DNS Fluxing) to deliver new Gamma malware variants, facilitating more than a thousand infections in a single day.
An examination of a sample of the lures associated with the ongoing activity reveals a focus on regional military, police and civil government training centers across Ukraine. In addition to collecting against Ukrainian combat capabilities, it is possible Hive0051 may seek to utilize access to gain advanced insight into the status of new security agreements and partners providing military training and material support to Ukraine.
https://securityintelligence.com/x-force/hive0051-all-in-triple-threat/
Regards
Caute_Cautim
Regards
Caute_Cautim