Gamaredon Group
MITRE ATT&CK: G0047 View on attack.mitre.org
Aliases: IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew, Blue Otso, BlueAlpha, PRIMITIVE BEAR, Trident Ursa, UAC-0010, Winterflounder, Actinium, Gamaredon Group, UNC530, Gamaredon, shuckworm, SectorC08
- First seen
- 2013-01-01 00:00:00
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 847 (12 malicious)
- Last IoC activity
- 2026-09-01 20:35:17
- Profile updated
- 2026-07-07 12:32:26
Targeted industries: defense-and-aerospace government-and-public-sector education-and-nonprofits
Targeted regions: country_code:ua
Context
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.
Recent IoC activity
12 malicious indicators in Maltiverse are attributed to Gamaredon Group (G0047). The 12 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.franceconsobanque.fr | 2026-09-03 | 2 |
| hostname | merafm.com | 2026-09-02 | 3 |
| IP address | 178.141.98.201 | 2026-08-20 | 4 |
| IP address | 115.55.195.102 | 2026-08-12 | 4 |
| IP address | 222.246.108.68 | 2026-08-11 | 4 |
| hostname | rssh.li | 2026-08-06 | 2 |
| hostname | 2021new.lietuzhe.com | 2026-03-29 | 2 |
| hostname | jiqaz.com | 2025-12-08 | 3 |
| hostname | mrassociattes.com | 2024-11-20 | 2 |
| hostname | autoacores.com | 2023-03-26 | 2 |
| hostname | www.erosaramtervezes-kivitelezes.hu | 2023-03-26 | 2 |
| hostname | presume.wtf | 2023-01-21 | 1 |
Detection coverage
- 5 YARA rules
- 995 Sigma rules
Malware & tools used
- Internal Defacement (attack-pattern)
- Virtual Private Server (attack-pattern)
- Data Obfuscation (attack-pattern)
- Internal Spearphishing (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Automated Collection (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Compile After Delivery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- VNC (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Rundll32 (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- System Information Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- Screen Capture (attack-pattern)
- Security Software Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Data from Network Shared Drive (attack-pattern)
- Upload Malware (attack-pattern)
- Compression (attack-pattern)
- One-Way Communication (attack-pattern)
Reports & references
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- researchcenter.paloaltonetworks.com — Unit 42 Title Gamaredon Group Toolset Evolution (report)
- lookingglasscyber.com — Operation Armageddon Final (report)
- Palo Alto Unit 42 — Unit 42 Title Gamaredon Group Toolset Evolution (report)
- MITRE ATT&CK — G0047 (report)
- github.com — Gamaredon (report)
- ESET — Digging Up Invisimole Hidden Arsenal (report)
- Broadcom/Symantec — Shuckworm Gamaredon Espionage Ukraine (report)
- Microsoft — Actinium Targets Ukrainian Organizations (report)
- ESET — Gamaredon Group Grows Its Game (report)
- Palo Alto Unit 42 — Gamaredon Primitive Bear Ukraine Update 2021 (report)
- go.recordedfuture.com — Cta 2019 1212 (report)
- Palo Alto Unit 42 — Tridentursa (report)
- CERT-UA — 1229152 (report)
- CERT-UA — 971405 (report)
- CERT-UA — 40240 (report)
- CERT-UA — 39386 (report)
- CERT-UA — 39086 (report)
- CERT-UA — 39138 (report)
- CERT-UA — 18365 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- blog.cloudflare.com — 2026 Threat Report (report)
- Trend Micro — Gamaredon Apt Group Use Covid 19 Lure In Campaigns (report)
Attributed from
- BlueAlpha Cloudflare Tunneling Activity (campaign)
External references
- mitre-attack — G0047
- Cloudflare 2026 Threat Report New Threat Actors March 2026
- NastyShrew
- ACTINIUM
- DEV-0157
- Aqua Blizzard
- Gamaredon Group
- IRON TILDEN
- Armageddon
- Shuckworm
- Primitive Bear
- ESET Gamaredon June 2020
- TrendMicro Gamaredon April 2020
- Palo Alto Gamaredon Feb 2017
- Microsoft Threat Actor Naming July 2023
- Microsoft Actinium February 2022
- Secureworks IRON TILDEN Profile
- Symantec Shuckworm January 2022
- Bleepingcomputer Gamardeon FSB November 2021
- Unit 42 Gamaredon February 2022