Risky Bulletin Newsletter
January 22, 2025
Risky Bulletin: Threat actor impersonates FSB APT for months to target Russian orgs
Presented by
News Editor
A cyber-espionage group has mimicked the tactics of an FSB-linked APT to target Russian organizations for months.
Named GamaCopy (or Core Werewolf), the group emulated the tactics of Gamaredon (or Armageddon), a cyber-espionage group operated by the Russian FSB intelligence agency from the occupied region of Crimea.
The group's false flag attacks have been taking place since June of last year. The campaign has tricked several security vendors who misattributed attacks to Gamaredon, according to a report from Chinese security firm Knownsec 404.