Gamaredon Group — APT Profile
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, Blue Otso, BlueAlpha, G0047, Trident Ursa, UAC-0010, Winterflounder
IntelFusions coverage (4)
- Russia's Gamaredon hides Ukraine spying behind everyday web services 2026-06-26 · Nation-State
- Russia-aligned hackers keep hitting Ukraine through an old WinRAR bug 2026-06-09 · Nation-State
- Russian FSB Hackers Hit Ukraine With a Self-Reinstalling Malware Chain 2026-06-06 · Nation-State
- Gamaredon Group: Russia's Most Prolific APT Against Ukraine, Powered by Custom Malware and SFX Persistence 2026-02-16 · Nation-State
Tools & malware
- apk.bone_spy Mobile Malware
- apk.plain_gnome Mobile Malware
- elf.evilgnome Backdoor
- Ping Network Reconnaissance
- PowerPunch Backdoor
- ps1.ptero_graphin Backdoor
- Pteranodon Backdoor
- QuietSieve Infostealer
- Reg LOLBin
- Remcos Remote Access Trojan
- vbs.gamawiper Wiper
- vbs.litterdrifter Worm
- vbs.unidentified_003 Backdoor
- vbs.unidentified_006 Backdoor
- win.dilongtrash Backdoor
- win.dinotrain Backdoor
- win.pteranodon Backdoor
- win.quietsieve Infostealer
Vendor research
- IRON TILDEN Secureworks CTU
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- How Microsoft names threat actors Microsoft
- The Gamaredon Group Toolset Evolution Palo Alto
- ACTINIUM targets Ukrainian organizations Microsoft
- Secureworks CTU. (n.d.). IRON TILDEN Secureworks
- Shuckworm Continues Cyber-Espionage Attacks Against Ukraine Symantec
- Ukraine links members of Gamaredon hacker group to Russian FSB Bleepingcomputer
- Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine Unit 42
- Gamaredon group grows its game ESET
- Gamaredon APT Group Use Covid-19 Lure in Campaigns TrendMicro