Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Gamaredon Group

Also known as: IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew, Gamaredon Group, BlueAlpha, Blue Otso, G0047, Trident Ursa, UAC-0010, Winterflounder

Description

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: TrendMicro Gamaredon April 2020)(Citation: ESET Gamaredon June 2020)(Citation: Symantec Shuckworm January 2022)(Citation: Microsoft Actinium February 2022) In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. (Citation: Bleepingcomputer Gamardeon FSB November 2021)(Citation: Microsoft Actinium February 2022)

TTP Summary

OP Armageddon; Op Gamework

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

IR

AI Analysis

· 1 week ago

Executive Summary

Gamaredon Group, a suspected Russian cyber espionage entity linked to the FSB's Center 18, has targeted Ukrainian government sectors since at least 2013. Known for sophisticated tactics including spear-phishing and malware deployment, the group has employed tools like QuietSieve and Pteranodon, often leveraging cloud services for infrastructure staging.

Goals & Targeting

Gamaredon Group's primary strategic objective appears to be espionage against military, law enforcement, and government targets, likely to gather sensitive intelligence for Russian interests. The group focuses on sectors that provide valuable political and military information, with a particular emphasis on Ukraine due to its geopolitical significance. Their targeting of NGOs and non-profits suggests an interest in broader societal influence as well.

Enhanced Description

Gamaredon Group, also known as IRON TILDEN, Primitive Bear, and ACTINIUM among other aliases, is a cyber espionage group believed to operate under the auspices of Russia's Federal Security Service (FSB). The group has been active since at least 2013 and has primarily targeted military, law enforcement, judiciary, non-profit, and NGOs in Ukraine. The name 'Gamaredon' is derived from a misspelling of 'Armageddon,' first appearing in early campaigns. The group's operations have evolved significantly over the years, with notable campaigns such as OP Armageddon and Op Gamework. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s FSB Center 18, a claim supported by cybersecurity researchers. Gamaredon is known for using sophisticated techniques including spear-phishing attacks, PowerShell-based activities, and malware deployment. The group has also been linked to the use of QuietSieve, Pteranodon, and PowerPunch tools. Gamaredon's targeting strategy focuses on high-value targets within critical sectors, leveraging cloud services for infrastructure staging and employing domain generation algorithms (DGAs) to maintain persistence. Their activities have raised concerns about the potential for broader impact in regions beyond Ukraine.

Key Capabilities

  • Spear-phishing campaigns
  • Malware deployment
  • PowerShell-based activities
  • Cloud service abuse
  • Domain generation algorithms (DGAs)
  • Sophisticated persistence mechanisms

MITRE ATT&CK Tactics

Collection
Exfiltration
Reconnaissance
Defense Evasion
Credential Access

ATT&CK Techniques

T1566.001
T1059.001
T1480
T1027
T1113
T1568.001
T1016.001

Software / Tooling

QuietSieve
Pteranodon
PowerPunch

Campaigns & Victims

Gamaredon Group's campaigns often involve long-term, persistent operations targeting critical infrastructure and government entities. Notable campaigns include OP Armageddon and Op Gamework, with the group frequently reusing or evolving tools like QuietSieve for data extraction. Their use of cloud services for infrastructure staging indicates a preference for low-profile operations that leverage legitimate service providers. Past activities have also included employment of fast-flux domains and VNC-based remote access.

IOC Patterns

  • Domain patterns with .trycloudflare.com subdomains
  • Use of specific IP addresses like 178.130.42.94
  • SHA-256 hashes associated with malware (e.g., 3afc8955057eb0bae8...)
  • URLs for file downloads and malicious scripts
  • Domestic Ukrainian domains for infrastructure

Recommended Actions

  • Implement email filtering for spear-phishing attempts
  • Monitor for known Gamaredon-associated domain patterns in cloud services
  • Enhance VNC and remote access protocol monitoring
  • Conduct regular endpoint scanning for known malware hashes
  • Secure shared network drives against unauthorized access

Suggested Tags

APT
espionage
government-targeted
Ukraine
Russia-linked

Confidence Assessment

The data on Gamaredon Group is extensive and corroborated by multiple sources, including cybersecurity firms and government reports. However, gaps exist in the exact timeline of their first activities and specific campaign timelines outside Ukraine.

ATT&CK Techniques

Collection
5 techniques
Command & Control
12 techniques
Defense impairment
2 techniques
Discovery
8 techniques
Execution
9 techniques
Lateral Movement
4 techniques
Resource Development
6 techniques
Stealth
17 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 1 URL 1 MD5 Hash 10 SHA-1 Hash 8

References

  1. Cloudflare 2026 Threat Report New Threat Actors March 2026 — Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
  2. ESET Gamaredon June 2020 — Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.
  3. TrendMicro Gamaredon April 2020 — Kakara, H., Maruyama, E. (2020, April 17). Gamaredon APT Group Use Covid-19 Lure in Campaigns. Retrieved May 19, 2020.
  4. Palo Alto Gamaredon Feb 2017 — Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.
  5. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  6. Microsoft Actinium February 2022 — Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.
  7. Secureworks IRON TILDEN Profile — Secureworks CTU. (n.d.). IRON TILDEN. Retrieved February 24, 2022.
  8. Symantec Shuckworm January 2022 — Symantec. (2022, January 31). Shuckworm Continues Cyber-Espionage Attacks Against Ukraine. Retrieved February 17, 2022.
  9. Bleepingcomputer Gamardeon FSB November 2021 — Toulas, B. (2018, November 4). Ukraine links members of Gamaredon hacker group to Russian FSB. Retrieved April 15, 2022.
  10. Unit 42 Gamaredon February 2022 — Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

Intel Summary

70

Techniques

3

Tools

4

Campaigns

601

IOCs

0

Observed Data

12

Tactics

Tags

APT
Government Targeting
espionage
government-targeted
Ukraine
Russia-linked

Details

MITRE ID
G0047
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--2e290bfe-93b5-48ce-97d6-edcd6d32b7cf
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.