Gamaredon Group — APT Profile
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.Also tracked as
IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard
Tools & malware
- apk.bone_spy Mobile Malware
- apk.plain_gnome Mobile Malware
- elf.evilgnome Backdoor
- Ping Network Reconnaissance
- PowerPunch Backdoor
- ps1.ptero_graphin Backdoor
- Pteranodon Backdoor
- QuietSieve Infostealer
- Reg LOLBin
- Remcos Remote Access Trojan
- vbs.gamawiper Wiper
- vbs.litterdrifter Worm
- vbs.unidentified_003 Backdoor
- vbs.unidentified_006 Backdoor
- win.dilongtrash Backdoor
- win.dinotrain Backdoor
- win.pteranodon Backdoor
- win.quietsieve Infostealer
Vendor research
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- How Microsoft names threat actors Microsoft
- IRON TILDEN Secureworks CTU
- The Gamaredon Group Toolset Evolution Palo Alto
- ACTINIUM targets Ukrainian organizations Microsoft
- Secureworks CTU. (n.d.). IRON TILDEN Secureworks
- Shuckworm Continues Cyber-Espionage Attacks Against Ukraine Symantec
- Ukraine links members of Gamaredon hacker group to Russian FSB Bleepingcomputer
- Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine Unit 42
- Gamaredon group grows its game ESET
- Gamaredon APT Group Use Covid-19 Lure in Campaigns TrendMicro