Overview

Platforms: Windows · Linux
Variants: TinyCrypt · decr1pt
Extensions: .crypt
ATT&CK software: Cobalt Strike · TinyPosh · TinyNode
Initial access: Phishing: Spearphishing Link
Top countries: RU · BY
Observed sectors: Banking · Manufacturing · Healthcare · Retail · Technology
Tracked victims: 16

Victims

SOTRANS CONFIRMED
January 26, 2025 Russia Transportation & Logistics
Russian transport and logistics group providing freight transport, fleet services and trailer manufacturing.
Undisclosed organization VERIFIED
August 2020 RU Healthcare Ransom demand: $50,000 Outcome: successful
Large clinical diagnostics / medical company with a regional branch network; public victim identity was not disclosed.
Undisclosed organization VERIFIED
2020 RU Manufacturing · Defense
Russian arms manufacturer; public victim identity was not disclosed.
8 undisclosed organizations VERIFIED
H1 2025 RU Manufacturing · Healthcare · Retail · Technology
Eight large Russian enterprises reported affected during renewed OldGremlin activity; individual victim identities were not publicly disclosed.
EuroAuto POSSIBLE
Russia Retail & E-Commerce Suspected victims
Russian auto-parts retailer and automotive service network.
CITILAB POSSIBLE
August 30, 2020 Russia Healthcare Suspected victims
Federal Russian clinical diagnostics laboratory network.

Operational Activity

Recent Observations

Lateral Movement and Credential Access
January 2021
Post-compromise activity includes the use of tools like Cobalt Strike and Mimikatz for lateral movement and credential harvesting within the victim environment.
Initial Access via Spear-Phishing
August 2020
OldGremlin primarily utilizes spear-phishing campaigns to gain initial access. These campaigns often involve emails containing malicious attachments, such as self-extracting archives (SFX) that execute loaders or backdoors.
Use of Custom Backdoors
August 2020
The group employs custom backdoors for persistence and command-and-control, including TinyNode and other specialized malware families designed to maintain access after initial infection.
Targeting of Russian Organizations
August 2020
OldGremlin activity is primarily focused on organizations within the Russian Federation, including industrial, financial, and logistics sectors.

TTPs

ATT&CK coverage: 4 techniques
T1566.002 Phishing: Spearphishing Link
VERIFIED
OldGremlin utilizes spearphishing emails containing links to malicious files, often hosted on legitimate cloud storage services or actor-controlled infrastructure, to facilitate initial access.
T1204.002 User Execution: Malicious File
VERIFIED
The actor relies on social engineering to trick victims into downloading and executing malicious payloads delivered via phishing.
T1071.001 Application Layer Protocol: Web Protocols
VERIFIED
The actor uses HTTP/HTTPS for command and control communication, often leveraging legitimate web services to blend in with normal traffic.
Show more TTPs (1)
T1486 Data Encrypted for Impact
VERIFIED
The group deploys custom ransomware to encrypt victim files as the final stage of their intrusion operations.

CVEs

Cisco — AnyConnect Secure Mobility Client for Windows
OldGremlin used this local privilege-escalation chain after compromise to place files through the AnyConnect downloader and support SYSTEM-level code execution.
Cisco — AnyConnect Secure Mobility Client for Windows
OldGremlin used AnyConnect DLL hijacking as part of a local exploit chain to execute code with SYSTEM privileges on an already compromised Windows host.
GIGABYTE — gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
Show more CVEs (4)
GIGABYTE — gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
GIGABYTE — gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
GIGABYTE — gdrv.sys
TinyKiller used the vulnerable signed GIGABYTE gdrv.sys driver in a BYOVD chain to load an unsigned OldGremlin kernel driver and stop antivirus processes.
Micro-Star International (MSI) — RTCore64.sys / RTCore32.sys
A second TinyKiller variant observed in 2022 used vulnerable RTCore drivers in a BYOVD workflow to stop endpoint-security processes.
Associated since: 2022

Infrastructure

ProtonMail contact
OldGremlin used campaign-specific ProtonMail addresses in ransom notes for victim communication.
Cloudflare Workers C2 proxy
Cloudflare Workers were used as an intermediary layer to conceal the real command-and-control server.
WebDAV staging infrastructure
OldGremlin used WebDAV servers to stage and deliver Node.js components and malicious JavaScript payloads.
DGA / DNS-tunneling C2
A TinyFluff variant generated C2 domains through a DGA and exchanged commands and data through DNS queries and TXT records.
Public Internet C2 servers
During renewed activity in 2025, OldGremlin operated command-and-control servers reachable directly from the public internet.

Attribution

TinyScouts PROBABLE
Vendor tracking name
An alias used to refer to the threat actor group OldGremlin.

Affiliates

No affiliate information available.

Timeline

2022-03
Shift in targeting during geopolitical instability
Group-IB reports that OldGremlin shifted its focus, intensifying attacks on Russian companies immediately following the start of the conflict in Ukraine, utilizing highly personalized spear-phishing campaigns.
2021-05
OldGremlin resumes activity after hiatus
After a period of inactivity, researchers observe OldGremlin initiating new campaigns using updated malware and delivery techniques targeting Russian organizations.
2020-08
First documented activity of OldGremlin
Group-IB identifies the emergence of the OldGremlin threat actor, noting their initial attacks against industrial and financial organizations in Russia.

Sources