Giddome Backdoor Linked to Russian Threat Actor

Security researchers with Symantec recently published a report on new activity conducted by Russian threat actors and aimed at Ukrainian targets.

The threat actor is known by several aliases, including Gamaredon and Shuckworm.

Researchers identified several different executable files as variants of the Giddome backdoor - a tool that is associated with Shuckworm. All files had the string "ntuser" at the start of their names. The file extensions were .VCD and .H264, one being a disk image file format and the other - a video file format.

The disk image and video file had child process executables with the same names, only with an .exe extension.

The Giddome has a rich set of malicious capabilities including recording and capturing audio using a microphone found on the victim system, taking screenshots and sending them to remote servers, keystroke logging and remote file downloading and execution capabilities.

The recent attacks that employed the Giddome backdoor to target entities in Ukraine also used compromised instances of remote desktop management tools such as AnyDesk and Ammyy Admin.

August 18, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.