GamaCopy

First seen
2021-08-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:20:38

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:ru

Context

GamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimicking the TTPs of Gamaredon. The organization has been active since at least August 2021 and primarily uses Russian-language bait documents related to military facilities. Analysis of attack samples shows considerable overlap in code structure and tactics, including the use of 7z-SFX documentation to install UltraVNC and connecting via port 443. GamaCopy employs open-source tools to obfuscate its activities while targeting sensitive information in the context of the Russia-Ukraine conflict.

Reports & references

  • medium.com — Love And Hate Under War The Gamacopy Organization Which Imitates The Russian Gamaredon Uses 560Ba5E633Fa (report)

External references