The Russia-linked Gamaredon espionage group—also tracked as ACTINIUM, Shuckworm, and Primitive Bear—has continued targeting Ukrainian government, military, security, and research organizations with large-scale intrusion activity, including thousands of attacks attributed by Ukraine’s SSU to FSB-linked operators. Microsoft and Symantec documented sustained campaigns using spear-phishing, malicious attachments, PowerShell, and VBScript malware to gain access, maintain persistence, and steal sensitive information such as military reports, arsenal inventories, and personnel data.
Check Point said the group added a newly identified VBS-based USB worm called LitterDrifter, which spreads through removable drives by planting hidden copies and malicious .lnk shortcuts while maintaining command-and-control through rapidly changing infrastructure. Researchers said the malware uses randomized subdomains of hardcoded .ru domains and can fall back to Telegram channels for C2 resolution, matching Gamaredon’s pattern of volatile infrastructure and frequent tool updates. Although the campaign remains focused on Ukraine, infections were also observed in countries including the United States, Vietnam, Chile, Poland, Germany, and Hong Kong, likely caused by uncontrolled USB propagation rather than deliberate targeting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Check Point reported indications of LitterDrifter infections in the United States, Vietnam, Chile, Poland, Germany, and Hong Kong. The researchers assessed these were likely caused by uncontrolled USB propagation rather than deliberate targeting.
On November 17, 2023, Check Point Research published analysis of LitterDrifter, a newly identified VBScript-based USB worm used by Gamaredon. The malware spreads via removable drives and maintains command-and-control access using randomized .ru domains with a Telegram fallback.
On June 15, 2023, Symantec published details of Shuckworm's ongoing espionage campaign, including use of phishing, Pterodo, likely Giddome, short-lived infrastructure, and a new USB-propagation PowerShell script. The report also highlighted Telegram and Telegraph use for command and control.
Symantec said some intrusions that began in February or March 2023 persisted until May 2023, with certain compromises lasting as long as three months. During these intrusions, the group sought military, personnel, and government information.
Symantec reported that the campaign's attacks largely began in February and March 2023, targeting Ukrainian military, security, research, and government organizations. Initial access commonly came through spear-phishing emails carrying malicious attachments.
Between January and April 2023, Symantec observed up to 25 new variants per month of Shuckworm PowerShell script obfuscation. The change reflected frequent toolset refreshes intended to complicate tracking and detection.
Symantec noted it had previously documented four variants of the Backdoor.Pterodo malware family in April 2022. Those variants used VBS droppers, scheduled-task persistence, and downloaded additional code from command-and-control servers.
Microsoft published reporting on February 4, 2022, describing ACTINIUM activity against Ukrainian organizations. The reference establishes public reporting on the group's operations against Ukraine by that date.
Symantec said the Russia-linked Shuckworm/Gamaredon group has focused almost exclusively on Ukrainian targets since 2014. The activity forms the long-running backdrop for later campaigns and tooling changes described in the references.
4 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcemicrosoft.com
Open sourcessu.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.