Also known as: Primitive Bear, ACTINIUM, Shuckworm, tracked as, Hive0051, Invisimole, UNC530, Gamaredon APT, Armageddon APT, Armageddon
Gamaredon is a state-sponsored cyber espionage group targeting Ukrainian government entities, defense organizations, and critical infrastructure. The group operates with high sophistication, leveraging GammaSteel malware—an advanced stealer that resides entirely in memory and employs Windows DPAPI encryption. GammaSteel uses the HKCU\Printers registry key to store 71 distinct payload functions, making it highly persistent and difficult to detect. The malware utilizes three simultaneous data collection mechanisms: timed drive scans, USB monitoring for air-gapped systems, and real-time file surveillance. Exfiltration is conducted via legitimate S3-compatible cloud storage services or fallback channels to operator-controlled servers. Gamaredon's tactics include extensive use of VBScript for evasion, Dead Drop Resolvers on platforms like Telegram and Mastodon for C2 configuration, and bidirectional backdoor capabilities enabling arbitrary remote code execution. The group demonstrates high operational rigor with server rotations every 24 hours, indicating significant resource deployment and technical expertise.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Gamaredon (also known as UAC-0010 or Armagedon) is a suspected Russian FSB-linked advanced persistent threat (APT) group conducting espionage against Ukrainian government, military, and critical infrastructure targets. The group's primary tool, GammaSteel malware, employs sophisticated techniques to steal data, including memory-resident operations and multiple data acquisition methods. Gamaredon’s activities pose significant risks to national security and highlight the need for enhanced cybersecurity measures in targeted sectors.
Goals & Targeting
Gamaredon's primary objectives appear to be intelligence gathering and cyber espionage to support Russian interests in Ukraine. The targeting of government and defense sectors aligns with efforts to compromise sensitive information related to national security, military operations, and critical infrastructure. As a group apparently linked to the FSB, Gamaredon is likely focused on undermining Ukrainian sovereignty and resilience against Russian aggression
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Gamaredon has been active since at least late 2019, targeting Ukrainian entities with highly customized and persistent attacks. Campaigns involve extensive use of both in-memory malware and file-based persistence mechanisms. The group's operational tempo is relatively high but seems to adapt based on victimology and detection pressures. Notable operations include compromises of government agencies, military units, and critical infrastructure sites in Ukraine, likely aiming to disrupt response capabilities during periods of heightened geopolitical tension.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence level: High, based on OSINT patterns, MISP reports, and K-reports. Data gaps include unclear origins beyond FSB associations and limited direct analysis of GammaSteel's source code.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
41
Tools
0
Campaigns
50
IOCs
0
Observed Data
13
Tactics