FORENSIA

THREAT_ACTOR · G0047

Gamaredon Group

Also known as: Gamaredon Group, IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew

Profile

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.

MITRE ATT&CK ↗

Techniques

70 ATT&CK techniques attributed to this actor.

T1001 Data ObfuscationT1005 Data from Local SystemT1012 Query RegistryT1016.001 Internet Connection DiscoveryT1020 Automated ExfiltrationT1021.005 VNCT1025 Data from Removable MediaT1027 Obfuscated Files or InformationT1027.004 Compile After DeliveryT1027.010 Command ObfuscationT1027.012 LNK Icon SmugglingT1027.015 CompressionT1027.016 Junk Code InsertionT1033 System Owner/User DiscoveryT1036.005 Match Legitimate Resource Name or LocationT1039 Data from Network Shared DriveT1041 Exfiltration Over C2 ChannelT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1055 Process InjectionT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1070.004 File DeletionT1071.001 Web ProtocolsT1080 Taint Shared ContentT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1090 ProxyT1090.003 Multi-hop ProxyT1091 Replication Through Removable MediaT1095 Non-Application Layer ProtocolT1102 Web ServiceT1102.002 Bidirectional CommunicationT1102.003 One-Way CommunicationT1105 Ingress Tool TransferT1106 Native APIT1112 Modify RegistryT1113 Screen CaptureT1119 Automated CollectionT1120 Peripheral Device DiscoveryT1137 Office Application StartupT1140 Deobfuscate/Decode Files or InformationT1204.001 Malicious LinkT1204.002 Malicious FileT1218.005 MshtaT1218.011 Rundll32T1221 Template InjectionT1480 Execution GuardrailsT1491.001 Internal DefacementT1497.001 System ChecksT1518.001 Security Software DiscoveryT1534 Internal SpearphishingT1547.001 Registry Run Keys / Startup FolderT1559.001 Component Object ModelT1561.001 Disk Content WipeT1564.003 Hidden WindowT1566.001 Spearphishing AttachmentT1568 Dynamic ResolutionT1568.001 Fast Flux DNST1571 Non-Standard PortT1583.001 DomainsT1583.003 Virtual Private ServerT1583.006 Web ServicesT1587.003 Digital CertificatesT1588.002 ToolT1608.001 Upload MalwareT1620 Reflective Code LoadingT1685 Disable or Modify Tools

Software

6 malware/tools attributed to this actor.

RegPingPteranodonRemcosPowerPunchQuietSieve

Related corpus activity

10,451 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Gamaredon Group.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
cve-2026-1969cve851
cve-2013-3307cve852
cve-2014-2321cve851
cve-2025-2492cve852
cve-2021-29441cve851
cve-2025-66478cve852
cve-2021-27076cve851
cve-2016-15047cve854
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2022-47945cve851
cve-2016-5681cve852
cve-2025-0921cve852
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-68670cve852
cve-2025-34054cve854
cve-2024-1781cve851
cve-2025-23304cve852
cve-2023-44976cveransomware852
cve-2020-17456cve851
cve-2020-22653cve852
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,451.