Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors gamaredon

Also known as: Primitive Bear, ACTINIUM, Shuckworm, tracked as, Hive0051, Invisimole, UNC530, Gamaredon APT, Armageddon APT, Armageddon

Description

Gamaredon is a state-sponsored cyber espionage group targeting Ukrainian government entities, defense organizations, and critical infrastructure. The group operates with high sophistication, leveraging GammaSteel malware—an advanced stealer that resides entirely in memory and employs Windows DPAPI encryption. GammaSteel uses the HKCU\Printers registry key to store 71 distinct payload functions, making it highly persistent and difficult to detect. The malware utilizes three simultaneous data collection mechanisms: timed drive scans, USB monitoring for air-gapped systems, and real-time file surveillance. Exfiltration is conducted via legitimate S3-compatible cloud storage services or fallback channels to operator-controlled servers. Gamaredon's tactics include extensive use of VBScript for evasion, Dead Drop Resolvers on platforms like Telegram and Mastodon for C2 configuration, and bidirectional backdoor capabilities enabling arbitrary remote code execution. The group demonstrates high operational rigor with server rotations every 24 hours, indicating significant resource deployment and technical expertise.

Goals & Targeting

Targeted Sectors

Government
Defense
Non profit
Media
Critical infrastructure

Targeted Countries / Regions

Ukraine
UA
RU
CN
CA
JP
DE

AI Analysis

· 1 week ago

Executive Summary

Gamaredon (also known as UAC-0010 or Armagedon) is a suspected Russian FSB-linked advanced persistent threat (APT) group conducting espionage against Ukrainian government, military, and critical infrastructure targets. The group's primary tool, GammaSteel malware, employs sophisticated techniques to steal data, including memory-resident operations and multiple data acquisition methods. Gamaredon’s activities pose significant risks to national security and highlight the need for enhanced cybersecurity measures in targeted sectors.

Goals & Targeting

Gamaredon's primary objectives appear to be intelligence gathering and cyber espionage to support Russian interests in Ukraine. The targeting of government and defense sectors aligns with efforts to compromise sensitive information related to national security, military operations, and critical infrastructure. As a group apparently linked to the FSB, Gamaredon is likely focused on undermining Ukrainian sovereignty and resilience against Russian aggression

Enhanced Description

Key Capabilities

  • GammaSteel malware: Memory-resident stealer with multiple data collection mechanisms
  • Use of Windows DPAPI encryption for credential theft
  • VBScript-based evasion techniques
  • Dead Drop Resolvers on social media platforms for C2
  • Bidirectional backdoor capabilities for remote code execution
  • High automation in infrastructure management (server rotations every 24 hours)
  • Spear-phishing capabilities using macro-laced Office documents

MITRE ATT&CK Tactics

Collection
Exfiltration
Exploitation
Defense Evasion
Lateral Movement
Discovery
Credential Access
Impact

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1003.001
T1078
T1218
T1040

Software / Tooling

GammaSteel malware
VBScript-based evasion tools
Dead Drop Resolvers
(Possible) Cobalt Strike-like frameworks
Mastodon/Telegram-based C2 infrastructure
Tebi.io S3-compatible cloud storage

Campaigns & Victims

Gamaredon has been active since at least late 2019, targeting Ukrainian entities with highly customized and persistent attacks. Campaigns involve extensive use of both in-memory malware and file-based persistence mechanisms. The group's operational tempo is relatively high but seems to adapt based on victimology and detection pressures. Notable operations include compromises of government agencies, military units, and critical infrastructure sites in Ukraine, likely aiming to disrupt response capabilities during periods of heightened geopolitical tension.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • VBScript files dropped as temporary files or registry entries
  • Registry modifications under HKCU\Printers
  • Malicious S3 traffic to Tebi.io-like domains
  • C2 communications via Telegram/Mastodon-based Dead Drop Resolvers
  • USB drive monitoring in air-gapped environments
  • Scheduled task creation for persistence

Recommended Actions

  • Implement strict controls over .exe, .vbs, and .dll file execution
  • Monitor cloud storage access patterns for unusual S3 activity
  • Enhance detection of suspicious processes using Process Monitor tools
  • Conduct regular USB device audits in air-gapped environments
  • Adopt network segmentation to mitigate lateral movement risks
  • Train users to recognize phishing attempts and report suspicious emails

Suggested Tags

APT
Cyber espionage
State-sponsored
Ukraine
Government
Defense sector
FSB关联

Confidence Assessment

Confidence level: High, based on OSINT patterns, MISP reports, and K-reports. Data gaps include unclear origins beyond FSB associations and limited direct analysis of GammaSteel's source code.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 5 Filename 2 SHA-256 Hash 4 URL 1 Domain 8

References

  1. apt.etda.or.th — Cited by web research for: T1193
  2. attack.mitre.org — Cited by web research for: T1583
  3. unit42.paloaltonetworks.com — Cited by web research for: Payload
  4. www.fortinet.com — Cited by web research for: Winrar
  5. blog.talosintelligence.com — Cited by web research for: Germany

Intel Summary

40

Techniques

41

Tools

0

Campaigns

50

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
Government Targeting
Cyber espionage
State-sponsored
Ukraine
Government
Defense sector
FSB关联

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.