Russian-speaking threat group OldGremlin carried out a series of ransomware and spearphishing attacks against organizations in Russia, an unusual targeting pattern for a financially motivated group operating in the region. Group-IB linked at least seven phishing campaigns since spring 2020 to the actor, with lures tied to COVID-19, media outreach, and the Belarus protests, while impersonating entities including RBC, SRO MiR, Novadent, Minsk Tractor Works, and a metallurgical company. Reported victims included a large medical company as well as banks and industrial firms.
In one documented intrusion, attackers used a phishing email masquerading as RBC to gain initial access, then deployed custom malware including TinyNode and TinyPosh, followed by Cobalt Strike for post-exploitation. The group established persistence through registry run keys, executed PowerShell and JScript, stole credentials, moved laterally over RDP and SMB, wiped backups, and finally encrypted the network with TinyCryptor ransomware. Group-IB said the operation also used Tor-based command-and-control infrastructure, APC-based process injection, and RC4-encrypted communications, aligning the activity with multiple MITRE ATT&CK techniques.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
On August 19, 2020, CERT-GIB detected OldGremlin campaigns targeting Russian financial organizations with emails impersonating Minsk Tractor Works. The lures referenced protests and strikes in Belarus.
On August 13 and 14, 2020, CERT-GIB tracked two large-scale OldGremlin campaigns impersonating RBC and a mining and metallurgical company. Around 250 malicious emails were sent to Russian companies in the financial and industrial sectors during the two days.
In a documented August 2020 incident, OldGremlin gained initial access to a large Russian medical company through a phishing email impersonating RBC with the subject line "Bill due." The intrusion deployed custom malware including TinyNode and led to broader post-exploitation activity.
On April 24, 2020, OldGremlin conducted a phishing attack impersonating the dental clinic Novadent. The campaign was part of the group's broader use of themed social engineering to deliver malware.
Group-IB estimated that OldGremlin conducted at least seven phishing campaigns starting in spring 2020. Early lures used COVID-19 themes and impersonated organizations including SRO MiR.
Group-IB first detected OldGremlin activity between late March and early April 2020. The early activity marked the emergence of a Russian-speaking ransomware group targeting organizations in Russia.
Three weeks after the initial infection, OldGremlin encrypted the medical company's entire corporate network, disrupting operations and demanding $50,000 in cryptocurrency. Before ransomware deployment, the attackers had moved laterally, obtained domain administrator credentials, and wiped backups.
About two weeks after the April 24 campaign, OldGremlin sent phishing emails posing as an RBC journalist inviting bank employees to a coronavirus-related survey interview. The attackers used Calendly and a follow-up cloud-upload message to make the lure appear legitimate.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.