Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Russia40 malware familiesExploits CVEs in the wild

Gamaredon Group

Also known asACTINIUMAPT-C-53Aqua BlizzardArmageddonDEV-0157gamaredongamaredon_groupIRON TILDENPRIMITIVE BEARSectorC08Shuckwormtrident_ursaUNC530

Gamaredon is a Russia-aligned advanced persistent threat group focused on cyberespionage against Ukraine. The content states the group has targeted Ukrainian governmental institutions since at least 2013, and in 2025 exclusively targeted Ukrainian government and military organizations. The Security Service of Ukraine attributes Gamaredon to the 18th Center of Information Security of Russia’s Federal Security Service (FSB), and one cited description identifies Armageddon as a unit of the FSB. Known aliases in the provided content include Actinium, APT-C-53, Aqua Blizzard, Armageddon, DEV-0157, Gamaredon, Iron Tilden, Primitive Bear, SectorC08, Shuckworm, Trident Ursa, UNC530, and BlueAlpha. The group is described as one of the most active Russia-aligned APT groups targeting Ukraine and maintained an aggressive cyberespionage campaign throughout 2025. ESET reported 35 distinct spearphishing campaigns in 2025, with most occurring in the second half of the year. Delivery methods mentioned include archive attachments, XHTML files using HTML smuggling, malicious hyperlinks, Office attachments with embedded malicious macros, malicious LNK files, and RAR archives exploiting CVE-2025-8088 to place HTA downloaders in Startup folders for execution at next login. Gamaredon expanded and refreshed its tooling in 2024 and 2025. The content states it developed six new PowerShell-based tools/downloaders in 2025 and also revived the VBScript weaponizer PteroSetup. Named tools and components mentioned include PteroPaste, PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, PteroSand, PteroPSDoor, PteroVDoor, PteroLNK, PteroGraphin, PteroStew, PteroQuark, PteroBox, PteroTickle, and PteroDespair. PteroPaste is described as combining downloader, USB weaponizer, and persistence-orchestration or runner functionality; it can copy a malicious downloader to connected USB drives while disguising it as a Word document shortcut, retrieve encrypted command-and-control information from Dropbox, and connect to infrastructure hidden behind tunneling services. Other tools fetched PowerShell or VBScript payloads, obtained C2 information from services such as Telegra.ph or GoFile, or supported lateral movement. The group’s tradecraft emphasizes simple but rapidly updated malware, persistent spearphishing, and concealment of infrastructure behind legitimate services. The content states Gamaredon used Cloudflare Tunnels, Cloudflare Workers, Microsoft dev tunnels, Loophole, dynamic DNS, PaaS platforms, No-IP, Clever Cloud, and Supabase to hide backend infrastructure. It also abused legitimate messaging, social media, blogging, paste, and cloud-storage services as dead drops or staging locations, including Telegram, Dropbox, GoFile, Mastodon, Rentry, Telegraph, Codeberg, and resolver websites. The group registered domains to stage payloads and used domains and third-party services to make detection and disruption more difficult. For execution and command and control, the content explicitly notes use of PowerShell, hidden execution via hidcon to run batch files in a hidden console window, and HTTP/HTTPS for C2 communications. Gamaredon tools decrypted additional payloads from C2, decoded Base64-encoded downloader source code, and decoded Telegram content to reveal C2 IP addresses. The group also deployed scripts on compromised systems that automatically scanned for interesting documents, listed files such as Office documents, and used macros that could scan for Microsoft Word and Excel files and inject additional malicious macros. Collection and exfiltration behavior in the content includes automated scanning for interesting documents, file listing, username gathering, and theft from removable media. A Gamaredon file stealer can gather the victim username for transmission to C2 and steal data from newly connected logical volumes, including USB drives. Updated stealers such as PteroPSDoor and PteroVDoor were reported to exfiltrate stolen files to S3-compatible cloud storage providers including Wasabi, Tebi, and Intercolo, with cloud storage becoming the group’s primary exfiltration method in 2025. The content also states that ESET observed collaboration between Gamaredon and the Russia-aligned Turla threat actor in early 2025, and notes prior collaboration with InvisiMole. One cited report says Gamaredon used its loader malware to provide initial access for Turla’s Kazuar framework. Overall, the provided material characterizes Gamaredon as a long-running, Russia-aligned FSB-linked espionage actor that persistently targets Ukrainian state and military entities through large-scale spearphishing, frequent tooling refreshes, USB propagation, and extensive abuse of legitimate online services to conceal command-and-control and exfiltration.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics63 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1587
Develop Capabilities
T1587.001
Malware
TA0001
Initial Access
3 techniques
T1091×3
Replication Through Removable Media
T1190
Exploit Public-Facing Application
T1566×3
Phishing
T1566.001×7
Spearphishing Attachment
T1566.002×3
Spearphishing Link
TA0002
Execution
4 techniques
T1053×2
Scheduled Task/Job
T1053.005
Scheduled Task
T1059×2
Command and Scripting Interpreter
T1059.001×6
PowerShell
T1059.005×5
Visual Basic
T1203×4
Exploitation for Client Execution
T1204
User Execution
T1204.002×4
Malicious File
TA0003
Persistence
4 techniques
T1053×2
Scheduled Task/Job
T1053.005
Scheduled Task
T1137
Office Application Startup
T1137.006
Add-ins
T1546
Event Triggered Execution
T1546.003
Windows Management Instrumentation Event Subscription
T1547
Boot or Logon Autostart Execution
T1547.001×4
Registry Run Keys / Startup Folder
T1547.009×2
Shortcut Modification
TA0004
Privilege Escalation
3 techniques
T1053×2
Scheduled Task/Job
T1053.005
Scheduled Task
T1546
Event Triggered Execution
T1546.003
Windows Management Instrumentation Event Subscription
T1547
Boot or Logon Autostart Execution
T1547.001×4
Registry Run Keys / Startup Folder
T1547.009×2
Shortcut Modification
TA0005
Stealth
6 techniques
T1006×2
Direct Volume Access
T1027×2
Obfuscated Files or Information
T1027.006×2
HTML Smuggling
T1036
Masquerading
T1140
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution
T1218.005×2
Mshta
T1564
Hide Artifacts
T1564.001
Hidden Files and Directories
T1564.003
Hidden Window
T1564.004
NTFS File Attributes
TA0007
Discovery
4 techniques
T1033
System Owner/User Discovery
T1082
System Information Discovery
T1083×2
File and Directory Discovery
T1135
Network Share Discovery
TA0008
Lateral Movement
2 techniques
T1091×3
Replication Through Removable Media
T1570
Lateral Tool Transfer
TA0009
Collection
3 techniques
T1005
Data from Local System
T1025
Data from Removable Media
T1119
Automated Collection
TA0011
Command and Control
5 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.002×4
External Proxy
T1090.003
Multi-hop Proxy
T1102×2
Web Service
T1102.001×4
Dead Drop Resolver
T1105×5
Ingress Tool Transfer
T1568×4
Dynamic Resolution
T1568.001
Fast Flux DNS
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002×4
Exfiltration to Cloud Storage
ARSENAL

Associated malware families

40 malware families attributed to this actor across reporting.

FamilyContextEvidenceLast seen
GammaLoadThat URL fetches GammaLoad, the intermediate staging layer... “GammaLoad (Staging): We recovered multiple VBScript loaders from the compromised hosts. It seems that these loaders operate in a continuous cascade, with four distinct execution stages observed during our analysis.”7Jun 4, 2026
PteranodonThe group was tied to the FSB by Ukraine’s Security Service, it originally used off-the-shelf tools like Remote Manipulator System RAT, then moved to a custom framework called Pteranodon, and gradually fragmented into a constellation of standalone, modular malware families.7Jun 4, 2026
PteroOddPteroOdd is a tiny downloader used to retrieve a single PowerShell payload via the Telegra.ph API, and based on what we observed, it appears to have been used mainly in cases connected to Gamaredon’s collaboration with Turla.7Jun 25, 2026
GammaPhishSekoia has now aligned the naming under a single taxonomy using the “Gamma” prefix: GammaPhish for initial access... “GammaPhish (Initial access): Through YARA-based hunting, we identified a cluster of weaponized xHTML files distributing a malicious RAR archive. This archive exploits the CVE-2025-8088 vulnerability to extract a hidden HTA file directly into the user’s Windows Startup directory.”6Jun 4, 2026
GammaWormGammaWorm is the propagation component... It doesn’t drop traditional files. Instead it writes its core modules into NTFS Alternate Data Streams... The propagation module targets USB drives and network shares.6Jun 4, 2026

35 additional families tracked in Mallory.

WEAPONIZED

Associated vulnerabilities

5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.

CVE-2025-8088WinRAR Windows Path Traversal via NTFS Alternate Data StreamsIn the wildEvidence14

As recently as November 2025, an email phishing wave targeting Ukraine was found to deliver the implant via RAR archives that exploit CVE-2025-8088, a WinRAR vulnerability that has been exploited by a number of Russian hacking groups such as Sandworm, Gamaredon, and RomCom.

CVE-2025-6218Directory Traversal RCE in RARLAB WinRARIn the wildEvidence3

Indicators of Compromise (IoCs):- ... CVE-2025-6218 WinRAR vulnerability used by Gamaredon/Sandworm/RomCom

CVE-2025-9491Microsoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityIn the wildEvidence2

This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.

CVE-2017-0199Microsoft Office/WordPad Remote Code Execution VulnerabilityIn the wildEvidence1

Документи ... містили шкідливий код для експлуатації відомої вразливості «Microsoft Office» CVE-2017-0199 ... що надає змогу зловмиснику виконати довільний код на пристрої користувача, при відкритті інфікованого файлу.

CVE-2018-20250WinRAR ACE Archive Path Traversal Arbitrary File WriteIn the wildEvidence1

Interestingly, the SSU documented Gamaredon leveraging this same TTP as early as 2018 exploiting CVE-2018-20250.

IOCS

Observables

289 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping45

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal40

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs5

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables289

Domains, IPs, and hashes tied to this actor, refreshed continuously.