Ukraine’s Security Service (SSU) publicly identified five alleged members of the Gamaredon cyber-espionage group and said the operators worked from Sevastopol, Crimea, under the direction of Russia’s FSB Center 18. The SSU said it issued high-treason notices and released intercepted calls to support its claims, marking a rare public attribution of the group to a named Russian security service. Ukrainian authorities said Gamaredon had operated since 2013 and carried out more than 5,000 cyberattacks against over 1,500 Ukrainian government systems, focusing on intelligence collection from security, defense, and law-enforcement bodies.
Reporting and threat tracking describe Gamaredon—also known as Armageddon, Shuckworm, Primitive Bear, Trident Ursa, ACTINIUM, DEV-0586, and UAC-0010—as a long-running Russian espionage actor that primarily targets Ukrainian state entities, with some activity extending to European institutions. The group is known for spearphishing and spoofed emails carrying malicious Office documents, macros, VBScript, PowerShell, and batch files, along with malware such as Pterodo/Pteranodon, GammaLoad, GammaDrop, GammaSteel, and QuietSieve. Analysts also link the actor to evasive infrastructure including dynamic DNS, fast-flux hosting, dead-drop resolvers, and Telegram- or GitHub-linked delivery and control mechanisms, as well as data theft, screenshot capture, remote access, and destructive actions such as file wiping and desktop defacement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
HarfangLab published a 2026 report describing Gamaredon's infection chain as using spoofed emails, GammaDrop, and GammaLoad. The report provided updated technical detail on the group's delivery and staging methods.
ClearSky referenced GamaWiper in connection with Gamaredon-related reporting in 2025. This added another malware component to the actor's publicly associated toolset.
Malpedia cites a 2025 ESET reference describing a Gamaredon and Turla collaboration involving PteroGraphin. This introduced a reported operational link between the two Russian threat actors.
HarfangLab published a 2025 report on Gamaredon's PteroLNK, describing dead-drop resolvers and evasive infrastructure. The report added technical detail on the group's command-and-control tradecraft.
Lookout reported in 2024 that it discovered two Russian Android spyware families from Gamaredon named BoneSpy and DroidWatcher. This expanded public understanding of the group's tooling into mobile surveillance malware.
ThreatMon published a 2023 technical analysis of an Armageddon infostealer called Cybergun. Malpedia includes this as part of the group's malware ecosystem documentation.
BlackBerry reported in January 2023 that Gamaredon abused Telegram to target Ukrainian organizations. The reporting highlighted Telegram-linked delivery or control mechanisms in the actor's operations.
Unit 42 published further reporting on Gamaredon in July 2022. Malpedia cites this as another public analytical milestone in tracking the actor's activity.
CERT-UA reported in April 2022 that UAC-0010/Armageddon had targeted state institutions of European Union countries. This marked documented activity beyond Ukrainian targets in the cited reporting.
Unit 42 published reporting in February 2022 on Gamaredon, including use of the alias Trident Ursa. Malpedia lists this as part of the actor's 2022 public reporting trail.
Microsoft published reporting in February 2022 stating that ACTINIUM, an alias for Gamaredon, targeted Ukrainian organizations. This added to public documentation of the group's sustained activity against Ukraine.
CERT-UA published reporting in 2022 linking UAC-0010 to GammaLoad and GammaSteel malware. The same year, CERT-UA also issued alerts about use of GammaLoad.PS1_v2.
CERT-UA reported cyberattacks by UAC-0010/Armageddon against state organizations of Ukraine in 2022. The reporting tied the activity to Gamaredon and its ongoing espionage campaigns.
The SSU publicly identified five alleged Gamaredon members, said they operated from Sevastopol, Crimea, and linked the group to Russia's FSB Center 18 in Moscow. The agency also said it issued notices of high treason and released intercepted phone conversations and a 35-page technical report.
ESET published reporting in 2020 stating that the Gamaredon group was expanding its operations. Malpedia includes this as part of the actor's evolving campaign history.
CERT-UA reported mass or bulk mailing campaigns in 2018 delivering Pterodo-type spyware associated with Gamaredon. This reflects one of the group's documented phishing-based malware delivery efforts.
A 2015 LookingGlass report titled "Operation Armageddon" documented the actor's cyber-espionage activity and framed it as part of Russian modern warfare. Malpedia cites this as one of the earliest public references in the group's reporting history.
The Ukrainian Security Service said the Gamaredon group began operating in June 2013. The group was later described as conducting cyberintelligence operations against Ukrainian state bodies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcesocradar.io
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.