An in-depth profile published by ThreatStop examines Gamaredon Group (aka Primitive Bear), the FSB-attributed Russian APT that has relentlessly targeted Ukrainian government organizations since at least 2013 — and whose operational tempo has accelerated dramatically since the outbreak of the Russo-Ukrainian war. Ukraine's Security Service (SSU) has publicly attributed the group to five Russian FSB officers stationed in Crimea, and has assessed Gamaredon as capable of surpassing even highly regarded Russian APTs such as APT28, Turla, and APT29 in the scale and damage of its attacks.
From Crimea Annexation to Cyber Warfare Front Line
Gamaredon's documented activity begins in 2013 — shortly before Russia's annexation of the Crimean peninsula — with a consistent focus on Ukrainian government entities and officials throughout its operational history. January 14, 2022 marked a significant escalation in Russian cyber operations, with coordinated defacement of Ukrainian government websites and WhisperGate wiper attacks against Ukrainian organizations. Gamaredon has been a persistent and active participant in Russia's broader cyber campaign throughout this period, operating as a high-volume, Ukraine-focused intrusion unit within the FSB's cyber apparatus.
Infection Tactics: Spear Phishing and Creative Delivery
Gamaredon's primary initial access vector is spear phishing via malicious Office file attachments, but the group has demonstrated adaptability in delivery mechanisms. In one documented campaign targeting a Western government entity, the attackers submitted a malicious downloader disguised as a CV directly to a job search platform — a targeted, patient approach that bypassed conventional email-based phishing detection entirely.
Once a malicious document is opened, a remote template injection technique retrieves a malicious VBS script from attacker-controlled infrastructure. The script then checks in with C2 servers and — after a deliberate delay of several hours (documented at six hours in observed cases) — downloads a Self-eXtracting (SFX) archive, one of Gamaredon's most consistent tradecraft signatures. These SFX archives bundle evasive remote access and persistence tools; current operations deliver UltraVNC, providing the C2 server with full interactive control over the compromised system, alongside additional VBS files and custom Gamaredon malware families.
Custom Malware Arsenal
Gamaredon has maintained a continuously developed suite of proprietary malware across its operational history:
- PowerPunch: The group's dropper and downloader family, sharing evasion characteristics with Pterodo, used to stage and execute subsequent payloads.
- Pterodo: A backdoor employing multiple obfuscation techniques that provides interactive network access to support hands-on-keyboard attacker activity.
- QuietSieve: An information-stealing implant that harvests documents (doc, docx, xls, rtf, odt, txt, pdf, rar, zip, 7z, jpg) and takes periodic screenshots, exfiltrating collected data to C2 infrastructure.
- ObfuMerry, ObfuBerry, DilongTrash, DinoTrain, DesertDown: Additional custom malware families deployed across different campaigns, reflecting the group's ongoing investment in proprietary tooling development.
Infrastructure: REG-RU and Shifting IP Spaces
Analysis of hundreds of historical and current Gamaredon indicators of compromise reveals a strong and consistent preference for the Russian domain registrar REG-RU across infrastructure registrations spanning the group's full operational history. The group actively rotates infrastructure over time — a documented operational security practice — though Cisco's mapping of Gamaredon-associated IP spaces has identified recurring patterns in the IP ranges the group favors for C2 hosting. This combination of registrar consistency and IP space preference provides network defenders with durable detection anchors even as specific domains and addresses change.