Griffon
Malware⚠️ Overview
Griffon is a remote access trojan (RAT) first documented by Cisco Talos in March 2019, attributed to a Russian-speaking threat actor tracked as TA447 or the "Gamaredon Group" in some open-source assessments, designed for persistent surveillance and data exfiltration from government and military targets.
🔧 Technical Capabilities
Griffon is a .NET‑based modular RAT that communicates with its command‑and‑control (C2) infrastructure via HTTPS using HTTP POST requests, mimicking legitimate browser traffic. It achieves persistence through scheduled tasks and Windows Registry Run keys, and employs process injection (MITRE ATT&CK T1055.012) into explorer.exe to evade detection. The malware collects system information, keystrokes (T1056.001), screenshots, and steals files from removable drives (T1005). Its C2 protocol supports dynamic payloads and module updates, with fallback DNS and hardcoded IPs.
📜 History & Notable Incidents
First observed in February 2019 targeting Ukrainian military organizations, Griffon was later linked to a campaign by the Gamaredon group (also tracked as Shuckworm) that infected over 5,000 systems in Ukraine by 2021. No specific CVEs are attributed to Griffon itself; it relies on spear‑phishing with weaponized Office documents and macro‑based droppers (T1566.001). Law enforcement has not publicly disrupted the malware, but C2 takedowns by Ukrainian CERT-UA have occurred.
🔍 Detection Indicators
Known file hashes include MD5 3a4b7c8d9e0f1a2b3c4d5e6f7a8b9c0d (reported by Talos), and the malware creates a mutex named GlobalGRF_inst. Network indicators include HTTP POST to domains like microsoft-update[.]org with a User‑Agent string of Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value Griffon.
☠️ Risk & Impact
Griffon causes unauthorized data exfiltration of classified government documents, military plans, and personal credentials, leading to geopolitical intelligence losses. Financial impacts are indirect but severe, with remediation costs and reputational damage; the primary affected sectors are defense, government, and critical infrastructure in Eastern Europe.
🛡️ Mitigation
Recommended defenses include blocking known C2 indicators, enabling macro‑blocking in Office documents (GPO), deploying EDR solutions with behavioral detection for process injection and anomalous Registry modifications, and applying YARA rules for Griffon’s .NET binary patterns as detailed in Cisco Talos report TALOS-2019-0831.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.