Overview
Platforms:
Windows · Linux
Variants:
TinyCrypt · decr1pt
Extensions:
.crypt
ATT&CK software:
Cobalt Strike · TinyPosh · TinyNode
Initial access:
Phishing: Spearphishing Link
Top countries:
RU · BY
Observed sectors:
Banking · Manufacturing · Healthcare · Retail · Technology
Tracked victims:
16
Victims
SOTRANS
CONFIRMED
Russian transport and logistics group providing freight transport, fleet services and trailer manufacturing.
Undisclosed organization
VERIFIED
Large clinical diagnostics / medical company with a regional branch network; public victim identity was not disclosed.
Undisclosed organization
VERIFIED
Russian arms manufacturer; public victim identity was not disclosed.
8 undisclosed organizations
VERIFIED
Eight large Russian enterprises reported affected during renewed OldGremlin activity; individual victim identities were not publicly disclosed.
EuroAuto
POSSIBLE
Russian auto-parts retailer and automotive service network.
CITILAB
POSSIBLE
Federal Russian clinical diagnostics laboratory network.
Operational Activity
Recent Observations
Lateral Movement and Credential Access
January 2021
Post-compromise activity includes the use of tools like Cobalt Strike and Mimikatz for lateral movement and credential harvesting within the victim environment.
Initial Access via Spear-Phishing
August 2020
OldGremlin primarily utilizes spear-phishing campaigns to gain initial access. These campaigns often involve emails containing malicious attachments, such as self-extracting archives (SFX) that execute loaders or backdoors.
Use of Custom Backdoors
August 2020
The group employs custom backdoors for persistence and command-and-control, including TinyNode and other specialized malware families designed to maintain access after initial infection.
Targeting of Russian Organizations
August 2020
OldGremlin activity is primarily focused on organizations within the Russian Federation, including industrial, financial, and logistics sectors.
TTPs
ATT&CK coverage:
4 techniques
T1566.002
Phishing: Spearphishing Link
VERIFIEDOldGremlin utilizes spearphishing emails containing links to malicious files, often hosted on legitimate cloud storage services or actor-controlled infrastructure, to facilitate initial access.
T1204.002
User Execution: Malicious File
VERIFIEDThe actor relies on social engineering to trick victims into downloading and executing malicious payloads delivered via phishing.
T1071.001
Application Layer Protocol: Web Protocols
VERIFIEDThe actor uses HTTP/HTTPS for command and control communication, often leveraging legitimate web services to blend in with normal traffic.
Show more TTPs (1)
T1486
Data Encrypted for Impact
VERIFIEDThe group deploys custom ransomware to encrypt victim files as the final stage of their intrusion operations.
CVEs
Cisco
— AnyConnect Secure Mobility Client for Windows
OldGremlin used this local privilege-escalation chain after compromise to place files through the AnyConnect downloader and support SYSTEM-level code execution.
Cisco
— AnyConnect Secure Mobility Client for Windows
OldGremlin used AnyConnect DLL hijacking as part of a local exploit chain to execute code with SYSTEM privileges on an already compromised Windows host.
GIGABYTE
— gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
Show more CVEs (4)
GIGABYTE
— gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
GIGABYTE
— gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
GIGABYTE
— gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
Micro-Star International (MSI)
— RTCore64.sys / RTCore32.sys
A second TinyKiller variant observed in 2022 used vulnerable RTCore drivers in a BYOVD workflow to stop endpoint-security processes.
Associated since:
2022
Infrastructure
ProtonMail contact
OldGremlin used campaign-specific ProtonMail addresses in ransom notes for victim communication.
Cloudflare Workers C2 proxy
Cloudflare Workers were used as an intermediary layer to conceal the real command-and-control server.
WebDAV staging infrastructure
OldGremlin used WebDAV servers to stage and deliver Node.js components and malicious JavaScript payloads.
DGA / DNS-tunneling C2
A TinyFluff variant generated C2 domains through a DGA and exchanged commands and data through DNS queries and TXT records.
Public Internet C2 servers
During renewed activity in 2025, OldGremlin operated command-and-control servers reachable directly from the public internet.
Attribution
TinyScouts
PROBABLE
Vendor tracking name
An alias used to refer to the threat actor group OldGremlin.
Affiliates
No affiliate information available.
Timeline
2022-03
Shift in targeting during geopolitical instability
Group-IB reports that OldGremlin shifted its focus, intensifying attacks on Russian companies immediately following the start of the conflict in Ukraine, utilizing highly personalized spear-phishing campaigns.
2021-05
OldGremlin resumes activity after hiatus
After a period of inactivity, researchers observe OldGremlin initiating new campaigns using updated malware and delivery techniques targeting Russian organizations.
2020-08
First documented activity of OldGremlin
Group-IB identifies the emergence of the OldGremlin threat actor, noting their initial attacks against industrial and financial organizations in Russia.
Sources
Show more sources (11)
OldGremlin hackers use Linux ransomware to attack Russian orgs
BleepingComputer