Gamaredon Group

MITRE ATT&CK: G0047 View on attack.mitre.org

Aliases: IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew, Blue Otso, BlueAlpha, PRIMITIVE BEAR, Trident Ursa, UAC-0010, Winterflounder, Actinium, Gamaredon Group, UNC530, Gamaredon, shuckworm, SectorC08

First seen
2013-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Related IoCs
847 (12 malicious)
Last IoC activity
2026-09-01 20:35:17
Profile updated
2026-07-07 12:32:26

Targeted industries: defense-and-aerospace government-and-public-sector education-and-nonprofits

Targeted regions: country_code:ua

Context

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.

Recent IoC activity

12 malicious indicators in Maltiverse are attributed to Gamaredon Group (G0047). The 12 most recently updated:

TypeIndicatorUpdatedSources
hostname www.franceconsobanque.fr 2026-09-03 2
hostname merafm.com 2026-09-02 3
IP address 178.141.98.201 2026-08-20 4
IP address 115.55.195.102 2026-08-12 4
IP address 222.246.108.68 2026-08-11 4
hostname rssh.li 2026-08-06 2
hostname 2021new.lietuzhe.com 2026-03-29 2
hostname jiqaz.com 2025-12-08 3
hostname mrassociattes.com 2024-11-20 2
hostname autoacores.com 2023-03-26 2
hostname www.erosaramtervezes-kivitelezes.hu 2023-03-26 2
hostname presume.wtf 2023-01-21 1

Detection coverage

  • 5 YARA rules
  • 995 Sigma rules

Malware & tools used

  • Internal Defacement (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • Data Obfuscation (attack-pattern)
  • Internal Spearphishing (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Automated Collection (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Compile After Delivery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • VNC (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Rundll32 (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Visual Basic (attack-pattern)
  • Screen Capture (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Data from Network Shared Drive (attack-pattern)
  • Upload Malware (attack-pattern)
  • Compression (attack-pattern)
  • One-Way Communication (attack-pattern)

Reports & references

  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • researchcenter.paloaltonetworks.com — Unit 42 Title Gamaredon Group Toolset Evolution (report)
  • lookingglasscyber.com — Operation Armageddon Final (report)
  • Palo Alto Unit 42 — Unit 42 Title Gamaredon Group Toolset Evolution (report)
  • MITRE ATT&CK — G0047 (report)
  • github.com — Gamaredon (report)
  • ESET — Digging Up Invisimole Hidden Arsenal (report)
  • Broadcom/Symantec — Shuckworm Gamaredon Espionage Ukraine (report)
  • Microsoft — Actinium Targets Ukrainian Organizations (report)
  • ESET — Gamaredon Group Grows Its Game (report)
  • Palo Alto Unit 42 — Gamaredon Primitive Bear Ukraine Update 2021 (report)
  • go.recordedfuture.com — Cta 2019 1212 (report)
  • Palo Alto Unit 42 — Tridentursa (report)
  • CERT-UA — 1229152 (report)
  • CERT-UA — 971405 (report)
  • CERT-UA — 40240 (report)
  • CERT-UA — 39386 (report)
  • CERT-UA — 39086 (report)
  • CERT-UA — 39138 (report)
  • CERT-UA — 18365 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • blog.cloudflare.com — 2026 Threat Report (report)
  • Trend Micro — Gamaredon Apt Group Use Covid 19 Lure In Campaigns (report)

Attributed from

  • BlueAlpha Cloudflare Tunneling Activity (campaign)

External references