{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Detecting the document scanning and exfiltration phase is the last opportunity to prevent the loss of sensitive data. Since Gamaredon heavily targets documents for espionage, a negative result across the estate provides critical assurance that active theft is not underway."
      },
      "name": "Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1041",
        "attack.t1047",
        "attack.t1059.001",
        "attack.t1555"
      ],
      "series": {
        "slug": "fsb-s-matryoshka-3-3-gamaredon-s-gammasteel-infostealer",
        "index": 2,
        "title": "FSB\u2019s matryoshka #3/3: Gamaredon's Gammasteel Infostealer",
        "total": 2
      },
      "related": [
        {
          "hunt": "gamaredon-gammaload-stager",
          "reason": "GammaLoad is responsible for the registry staging that the orchestrator analyzed in this hunt later retrieves and executes.",
          "relation": "precedes"
        },
        {
          "hunt": "gammasteel-registry-staging",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple detection rule on tebi.io or WMI commands might be too noisy in environments with heavy administrative automation. This hunt pivots between the unique script-based timer logic (3.6m ms) and the rare combination of profile/disk discovery across three different telemetry surfaces, using stack-counting to isolate the stealer.",
      "coverage": [
        {
          "stage": "drive-and-profile-discovery",
          "steps": [
            "orchestrator-timer-logic",
            "rare-wmi-discovery"
          ],
          "status": "covered"
        },
        {
          "stage": "s3-exfiltration",
          "steps": [
            "exfil-dns-lookups"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-powershell-dropper",
          "reason": "This is handled in the GammaLoad hunt, which focuses on the initial execution and staging.",
          "status": "out_of_scope"
        },
        {
          "stage": "registry-payload-staging",
          "reason": "Registry staging requires detailed analysis of HKCU\\Printers hive writes, belonging to a loader-focused hunt.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-run-key-pointer",
          "reason": "A standard detection rule for suspicious Run keys already covers the persistence mechanism used to relaunch the orchestrator.",
          "status": "existing_rule"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "PowerShell Dropper Execution",
            "slug": "execution-powershell-dropper",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "powershell.exe -nol -nop -enc",
              "Start-Process -FilePath \"powershell\" -ArgumentList \"-noexit\"",
              "-WindowStyle Hidden",
              "Global\\assembly307"
            ]
          },
          {
            "name": "Fileless Registry Staging via DPAPI",
            "slug": "registry-payload-staging",
            "tactic": "defense-evasion",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "HKCU\\Printers",
              "KeZdDboas5kpxbkgxxvBx",
              "ConvertTo-SecureString",
              "ConvertFrom-SecureString",
              "71 PowerShell functions"
            ]
          },
          {
            "name": "Persistence via Run Key Pointer",
            "slug": "persistence-run-key-pointer",
            "tactic": "persistence",
            "techniques": [
              "T1547.001"
            ],
            "observables": [
              "HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
              "Value name: $env:os",
              "YxwHku2chu0bznt3kkyAB",
              "powershell.exe -w hidden -command \"$a='HKCU:\\Printers'; $b=Get-ItemProperty ...\""
            ]
          },
          {
            "name": "WMI Drive and Profile Discovery",
            "slug": "drive-and-profile-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1047",
              "T1555"
            ],
            "observables": [
              "gwmi win32_userprofile",
              "S-1-5-21",
              "Get-PSDrive -PSProvider FileSystem",
              "Get-CimInstance Win32_LogicalDisk",
              "System.Timers.Timer",
              "Interval: 3600000"
            ]
          },
          {
            "name": "Data Exfiltration to S3 Storage",
            "slug": "s3-exfiltration",
            "tactic": "exfiltration",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "tebi.io",
              "MD5 hash deduplication log",
              "plLmfuh4uctxjtrQSXC"
            ]
          }
        ],
        "summary": "Gamaredon's GammaSteel infostealer utilizes an advanced fileless mechanism, staging 71 encrypted PowerShell functions directly in the Windows registry using DPAPI. The malware achieves persistence through Run key pointers and employs recurring WMI-based scans and hardware listeners to identify and exfiltrate user documents to S3-compatible cloud storage."
      },
      "severity": "high",
      "rationale": "Prioritize workstations and file servers where sensitive documents are stored. Ensure PowerShell Script Block Logging (Event ID 4104) is enabled, as the hunt relies on script text visibility.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Hosts identified in the scoping step; leave empty to hunt across the entire estate."
        },
        "exfil_domains": {
          "from": {
            "ref": "sekoia",
            "kind": "article",
            "observed": "2026-06-11"
          },
          "type": "list[domain]",
          "default": [
            "tebi.io"
          ],
          "description": "Known exfiltration domains used by Gammasteel."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "timer_interval": {
          "from": {
            "ref": "sekoia",
            "kind": "article",
            "observed": "2026-06-11"
          },
          "type": "string",
          "default": "3600000",
          "description": "The one-hour interval in milliseconds used by the orchestrator timer."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel",
          "name": "FSB\u2019s matryoshka #3/3: Gamaredon's Gammasteel Infostealer"
        }
      ],
      "blind_spots": [
        {
          "id": "script-logging-gap",
          "risk": "The hunt may miss the initial orchestrator trigger, relying solely on process discovery commands and DNS traffic which are easier for admins to overlook.",
          "stage": "drive-and-profile-discovery",
          "question": "whether the orchestrator script executed if block logging is disabled or if the script is heavily obfuscated",
          "requires": "hb_script_activity with full block logging enabled"
        },
        {
          "id": "s3-provider-rotation",
          "risk": "The hunt matches specific known domains; a new infrastructure choice makes the exfiltration invisible to the DNS step.",
          "stage": "s3-exfiltration",
          "question": "whether the adversary has rotated from tebi.io to another S3 provider",
          "requires": "hb_http_activity"
        }
      ]
    },
    "name": "Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration",
    "description": "This hunt targets the document discovery and exfiltration phase of Gammasteel, a modular stealer used by Gamaredon. The adversary establishes a one-hour recurring timer in PowerShell to trigger document scanning across all user profiles and logical disks. The hunt identifies this timer-based orchestration in script blocks, then fans out to detect the resulting WMI discovery commands and DNS resolutions to the known S3-compatible exfiltration provider. By pivoting from script-based triggers to prevalence-filtered process commands, the hunt separates automated malicious discovery from standard administrative activity."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "fsb-s-matryoshka-3-3-gamaredon-s-gammasteel-infostealer",
          "index": 2,
          "title": "FSB\u2019s matryoshka #3/3: Gamaredon's Gammasteel Infostealer",
          "total": 2
        },
        "coverage": [
          {
            "stage": "drive-and-profile-discovery",
            "steps": [
              "orchestrator-timer-logic",
              "rare-wmi-discovery"
            ],
            "status": "covered"
          },
          {
            "stage": "s3-exfiltration",
            "steps": [
              "exfil-dns-lookups"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-powershell-dropper",
            "reason": "This is handled in the GammaLoad hunt, which focuses on the initial execution and staging.",
            "status": "out_of_scope"
          },
          {
            "stage": "registry-payload-staging",
            "reason": "Registry staging requires detailed analysis of HKCU\\Printers hive writes, belonging to a loader-focused hunt.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-run-key-pointer",
            "reason": "A standard detection rule for suspicious Run keys already covers the persistence mechanism used to relaunch the orchestrator.",
            "status": "existing_rule"
          }
        ],
        "rationale": "An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.",
        "blind_spots": [
          {
            "id": "script-logging-gap",
            "risk": "The hunt may miss the initial orchestrator trigger, relying solely on process discovery commands and DNS traffic which are easier for admins to overlook.",
            "stage": "drive-and-profile-discovery",
            "question": "whether the orchestrator script executed if block logging is disabled or if the script is heavily obfuscated",
            "requires": "hb_script_activity with full block logging enabled"
          },
          {
            "id": "s3-provider-rotation",
            "risk": "The hunt matches specific known domains; a new infrastructure choice makes the exfiltration invisible to the DNS step.",
            "stage": "s3-exfiltration",
            "question": "whether the adversary has rotated from tebi.io to another S3 provider",
            "requires": "hb_http_activity"
          }
        ],
        "scoping_notes": "Prioritize workstations and file servers where sensitive documents are stored. Ensure PowerShell Script Block Logging (Event ID 4104) is enabled, as the hunt relies on script text visibility.",
        "beyond_detection": "A simple detection rule on tebi.io or WMI commands might be too noisy in environments with heavy administrative automation. This hunt pivots between the unique script-based timer logic (3.6m ms) and the rare combination of profile/disk discovery across three different telemetry surfaces, using stack-counting to isolate the stealer."
      }
    },
    {
      "id": "orchestrator-timer-logic",
      "type": "query",
      "label": "Search for orchestrator timer logic",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, script_path, script_content, time FROM hb_script_activity WHERE (script_content LIKE '%{{timer_interval}}%' OR LOWER(script_content) LIKE '%pllmfuh4uctxjtrqsxc%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Find PowerShell script blocks containing the specific one-hour timer interval or the Gammasteel orchestrator function name.",
        "expected_signal": "Script blocks defining a System.Timers.Timer with a 3.6m ms interval. Silence means no scripts matching these specific orchestrator patterns were logged."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Search for orchestrator timer logic",
        "reads": [
          "device_hostname",
          "script_content",
          "script_path",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, script_path, script_content, time FROM hb_script_activity WHERE (script_content LIKE '%{{timer_interval}}%' OR LOWER(script_content) LIKE '%pllmfuh4uctxjtrqsxc%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script blocks defining a System.Timers.Timer with a 3.6m ms interval. Silence means no scripts matching these specific orchestrator patterns were logged.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "exfil-dns-lookups",
      "type": "query",
      "label": "DNS lookups to exfiltration domains",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, COUNT(*) AS lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{exfil_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, query_hostname",
        "surface": "hb_dns_activity",
        "description": "Match host DNS traffic against known Gamaredon exfiltration infrastructure.",
        "expected_signal": "Connections to tebi.io, especially from PowerShell processes. Silence suggests a shift in infrastructure or absence of the exfiltration phase."
      },
      "parents": [
        {
          "id": "orchestrator-timer-logic"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS lookups to exfiltration domains",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, COUNT(*) AS lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{exfil_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, query_hostname",
        "silence": "not_evidence_of_absence",
        "expected": "Connections to tebi.io, especially from PowerShell processes. Silence suggests a shift in infrastructure or absence of the exfiltration phase.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-wmi-discovery",
      "type": "query",
      "label": "Rare WMI discovery commands",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%win32_userprofile%' OR LOWER(process_cmd_line) LIKE '%win32_logicaldisk%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY cmd HAVING hosts <= 3 ORDER BY hosts",
        "surface": "hb_process_activity",
        "description": "Identify rare execution of WMI queries for user profiles or logical disks that separate the stealer from normal admin noise.",
        "expected_signal": "PowerShell or WMIC commands enumerating profiles or drives on a small number of hosts. Large host counts indicate standard environment discovery."
      },
      "parents": [
        {
          "id": "orchestrator-timer-logic"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare WMI discovery commands",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%win32_userprofile%' OR LOWER(process_cmd_line) LIKE '%win32_logicaldisk%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY cmd HAVING hosts <= 3 ORDER BY hosts",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "PowerShell or WMIC commands enumerating profiles or drives on a small number of hosts. Large host counts indicate standard environment discovery.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-stealer-behavior",
      "type": "analytic",
      "label": "Triage stealer behavior",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "orchestrator-timer-logic",
          "exfil-dns-lookups",
          "rare-wmi-discovery"
        ],
        "objective": "Determine if the PowerShell activity represents an automated document exfiltration tool by correlating the script timer logic with the subsequent drive discovery and network traffic.",
        "description": "Evaluate whether the combination of orchestrator logic, WMI discovery, and exfiltration traffic indicates an active Gammasteel infection.",
        "max_iterations": 4,
        "expected_signal": "A host-by-host analysis of the evidence.",
        "success_criteria": "A verdict of malicious | suspicious | benign citing specific rows and script content segments."
      },
      "parents": [
        {
          "id": "exfil-dns-lookups",
          "kind": "merge"
        },
        {
          "id": "rare-wmi-discovery",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "evaluate-verdict",
      "type": "checkpoint",
      "label": "Evaluate verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-stealer-behavior verdict is malicious for at least one host, particularly where script timer logic and exfiltration domains appear together",
        "condition": "the triage-stealer-behavior verdict is malicious for at least one host, particularly where script timer logic and exfiltration domains appear together",
        "blind_spot": "script-logging-gap",
        "confidence": "high",
        "description": "Route the hunt based on the triage verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-stealer-behavior"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate endpoint",
      "config": {
        "target": "endpoint",
        "description": "Immediately contain the host to stop further document theft.",
        "instructions": "Isolate the host from the network and preserve the PowerShell event logs and registry hives for HKCU\\Printers.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "evaluate-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-re-review",
      "type": "task",
      "label": "Detailed analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the findings and identify the specific data targeted for exfiltration.",
        "instructions": "Examine hb_file_activity for the suspicious PowerShell process to determine which user documents were accessed. Check for the presence of the Global\\assembly307 mutex to confirm Gammasteel orchestrator execution."
      },
      "parents": [
        {
          "id": "evaluate-verdict",
          "branch": "default"
        },
        {
          "id": "evaluate-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "archive-hunt",
      "type": "task",
      "label": "Archive hunt",
      "config": {
        "assignee": "analyst",
        "description": "Record results and findings for future reference.",
        "instructions": "Summarize the hosts that showed timer activity vs those that showed DNS exfiltration. Note any false positives from legitimate administrative WMI scripts."
      },
      "parents": [
        {
          "id": "evaluate-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}