Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

GAMYBEAR

GAMYBEAR is a Go-based backdoor used in phishing-led intrusions targeting Ukrainian organizations, including educational institutions, state authorities, and, in CERT-UA reporting, activity tracked as UAC-0241. Observed delivery chains used ZIP archives containing a Windows LNK file that triggered mshta.exe to run an HTA, which launched JavaScript and then PowerShell to download and execute follow-on payloads. In one reported campaign, a password-protected ZIP hosted on Google Drive contained a shortcut that downloaded and executed zvit.hta, which retrieved update.js and then updater.ps1. GAMYBEAR was deployed alongside other payloads including LaZagne, a .NET-based file or PowerShell stealer, and reverse-shell functionality.

Its core functionality is to receive commands from a command-and-control server, execute them on the compromised host, and send results back to the server over HTTP, with data BASE64-encoded. Reported behavior also includes generating a UUID, collecting system information, storing C2 details in %APPDATA%\updater.json, and establishing persistence via a Windows Run registry key. CERT-UA described it as a listener/executor/sender style implant implemented in Go.

High-confidence infrastructure and campaign details directly mentioned in the content include HTTP C2 communications and an indicator of 185.223.93.102 as a GAMYBEAR C2 in one campaign. Related reporting tied UAC-0241 activity to spear-phishing against Ukrainian educational institutions and government bodies, especially in the Sumy region, using compromised email accounts and social-engineering lures. The malware is associated in the provided content with UAC-0241 operations against Ukrainian institutions.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAC-0241

Попередня Кібератака UAC-0241 у відношенні навчального закладу на сході України з використанням програмного засобу GAMYBEAR (CERT-UA#18329)

via cert uacert.gov.ua
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

breakglass intelNews
Mar 5, 2026
Dissecting a Ukraine-Targeted LNK Campaign: Cyrillic Homoglyphs, Fileless PowerShell, and Bulletproof Hosting - Breakglass Intelligence - Breakglass Intelligence

Named malware/tool referenced in comparison to another Ukrainian-targeting delivery chain using LNK, HTA, PowerShell, and Go.

Read more
the hacker newsNews
Jan 14, 2026
PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces

Go-based backdoor delivered via spear-phishing chain (LNK→HTA→JS→PowerShell) that executes server-issued commands and returns results base64-encoded over HTTP.

Read more
cert uaNews
Jan 12, 2026
"Неблагонадійний фонд": цільові кібератаки UAC-0190 у відношенні СОУ з використанням PLUGGYAPE (CERT-UA#19092)

Попередня Кібератака UAC-0241 у відношенні навчального закладу на сході України з використанням програмного засобу GAMYBEAR (CERT-UA#18329)

Read more
cert uaNews
Nov 18, 2025
Кібератака UAC-0241 у відношенні навчального закладу на сході України з використанням програмного засобу GAMYBEAR (CERT-UA#18329)

GAMYBEAR is a Go-based backdoor that enables remote command execution and exfiltration of results to a command and control server over HTTP. It generates a unique identifier, collects system information, and maintains persistence via registry keys. It communicates with its C2 using JSON and BASE64 encoding.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.