Gamaredon Group

Last Updated

Also known as: ACTINIUM, Actinium, Aqua Blizzard, Armageddon, Blue Otso, BlueAlpha, DEV-0157, FSB 16th & 18th Centers, G0047, Gamaredon, Gamaredon - APT-C-53, Gamaredon Group, Hive0051 (IBM), IRON TILDEN, Iron Tilden, NastyShrew, Primitive Bear, PRIMITIVE BEAR, SectorC08, Shuckworm, shuckworm, Trident Ursa, UAC-0010, UNC530, Winterflounder

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word “Armageddon,” found in early campaigns. Palo Alto Gamaredon Feb 2017 TrendMicro Gamaredon April 2020 ESET Gamaredon June 2020 Symantec Shuckworm January 2022 Microsoft Actinium February 2022

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. Bleepingcomputer Gamardeon FSB November 2021 Microsoft Actinium February 2022

🌍 Country Russia
📅 Activity 2022 — 2022
📝 Last Updated
🧭 ATT&CK G0047
Government
2022
2022

Introduction

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word “Armageddon,” found in early campaigns. Palo Alto Gamaredon Feb 2017 TrendMicro Gamaredon April 2020 ESET Gamaredon June 2020 Symantec Shuckworm January 2022 Microsoft Actinium February 2022 In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. Bleepingcomputer Gamardeon FSB November 2021 Microsoft Actinium February 2022

Activities and Tactics

Targeted Sectors: Government

Country of Origin: 🇷🇺 Russia

First Seen: 2022

Last Activity: 2022

Suspected Victims: Ukraine, Germany

Notable Campaigns

  • OP Armageddon
  • Op Gamework

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 4 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • Archelaus Beta
  • Pterodo:
  • QuietSieve:
  • DessertDown:
  • DinoTrain:

MITRE ATT&CK Software

Russian APT Tool Matrix observations

Category Observed tools
Credential Theft Mimikatz
Exfiltration Rclone, Telegram
LOLBAS PsExec
Networking Cloudflared, Ngrok, telegra[.]ph, teletype[.]in, trycloudflare[.]com
RMM Tools Remote Manipulator System (RMS), UltraVNC

Attribution and Evidence

Country of Origin: Russia Additional attribution information pending cataloguing.

References

[1] mitre-attack [2] Cloudflare 2026 Threat Report New Threat Actors March 2026 Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026. [12] ESET Gamaredon June 2020 Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020. [13] TrendMicro Gamaredon April 2020 Kakara, H., Maruyama, E. (2020, April 17). Gamaredon APT Group Use Covid-19 Lure in Campaigns. Retrieved May 19, 2020. [14] Palo Alto Gamaredon Feb 2017 Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017. [15] Microsoft Threat Actor Naming July 2023 Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023. [16] Microsoft Actinium February 2022 Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022. [17] Secureworks IRON TILDEN Profile Secureworks CTU. (n.d.). IRON TILDEN. Retrieved February 24, 2022. [18] Symantec Shuckworm January 2022 Symantec. (2022, January 31). Shuckworm Continues Cyber-Espionage Attacks Against Ukraine. Retrieved February 17, 2022. [19] Bleepingcomputer Gamardeon FSB November 2021 Toulas, B. (2018, November 4). Ukraine links members of Gamaredon hacker group to Russian FSB. Retrieved April 15, 2022. [20] Unit 42 Gamaredon February 2022 Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.