Gamaredon is a Russian state-linked cyber-espionage threat actor primarily focused on Ukraine. It is widely tracked under aliases including Armageddon, Shuckworm, Primitive Bear, Trident Ursa, ACTINIUM, APT-C-53, Aqua Blizzard, BlueAlpha, Iron Tilden, SectorC08, UAC-0010, and UNC530. Public reporting has repeatedly associated the group with Russia’s Federal Security Service (FSB), including attribution linking operators in occupied Crimea to the FSB’s Center for Information Security. The group has been active since at least 2013 and has conducted sustained intelligence collection operations against Ukrainian state entities, especially security, defense, military, and law-enforcement organizations, with some activity also affecting European government institutions. Gamaredon is known for high-volume, persistent operations that prioritize access and collection over stealth. Its campaigns frequently rely on spearphishing with malicious attachments, weaponized Office documents, embedded macros, remote template injection, and VBScript- or VBA-based execution chains. The actor has used malware and components including Pterodo or Pteranodon, GammaLoad, GammaDrop, GammaSteel, QuietSieve, DilongTrash, DinoTrain, BoneSpy, DroidWatcher, Cybergun, and other loaders, stealers, and backdoors. Reporting also describes abuse of Telegram in parts of its delivery or control infrastructure and use of dead-drop resolver techniques in later tooling. Observed tradecraft includes initial access via phishing, staged payload delivery, compilation of downloader source code directly on victim systems, execution through PowerShell and mshta, hidden-window execution, scheduled-task persistence, and Registry-based weakening of Office macro security controls. Gamaredon tooling has been documented gathering host and user information, enumerating processes, scanning for documents, stealing files, taking periodic screenshots, downloading and decrypting additional payloads, and maintaining persistence through Run-key mechanisms and scheduled execution. The actor is notable for aggressive, iterative operations and frequent tooling changes while remaining centered on espionage against Ukrainian government and military-related targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
50 malware families attributed to this actor across reporting.
45 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Investigating Gamaredon’s abuse of CVE-2025-8088, we identified a dozen waves of spearphishing emails against Ukrainian state institutions in a campaign that is still active, dating back to September 2025.
Indicators of Compromise (IoCs):- ... CVE-2025-6218 WinRAR vulnerability used by Gamaredon/Sandworm/RomCom
Analysts assess that Culver Aviation (a Ukrainian aviation company) probably has been targeted by multiple phishing lures containing malicious Word documents that use the CVE-2017-0199 vulnerability, which is exploited to execute the malware on victim systems through specially crafted Word documents. The Malicious Word document leverages the exploit CVE-2017-0199 to download and execute remote templates as a second stage of the malware. This exploit can be triggered by opening the Word document without any macro involvement.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Interestingly, the SSU documented Gamaredon leveraging this same TTP as early as 2018 exploiting CVE-2018-20250.
799 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state-linked threat actor mentioned as part of persistent campaigns targeting Ukraine in the lead-up to and during the broader conflict.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
FSB-linked Russian group conducting large-scale attacks against Ukrainian government institutions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.