Gamaredon is a Russia-aligned cyberespionage threat actor widely assessed as linked to the Russian Federal Security Service (FSB), including reporting that ties it to the FSB’s 18th Center of Information Security. The group is primarily focused on Ukraine and has conducted sustained, large-scale operations against Ukrainian government, military, security, and other critical-sector organizations. Common aliases include Actinium, Armageddon, Aqua Blizzard, Primitive Bear, Shuckworm, Trident Ursa, Iron Tilden, DEV-0157, UAC-0010, UNC530, APT-C-53, SectorC08, and Earth Dahu. Gamaredon is notable for high operational tempo, persistent access operations, and broad spearphishing activity rather than exceptional stealth or technical sophistication. Its campaigns frequently use malicious documents, archive attachments, XHTML and HTML-smuggling lures, and script-heavy infection chains built around obfuscated PowerShell, VBScript, and VBA macros. The group has repeatedly targeted Ukrainian entities with themed lures impersonating official communications and has used downloaders, web-shell-like implants, and follow-on payloads to establish footholds, execute remote commands, and deploy additional malware. The group’s malware ecosystem includes families and components such as GammaPhish, GammaWorm, GammaLoad, GammaSteel, Pterodo, PteroSand, PteroLNK, PteroPaste, PteroSetup, PteroDee, PteroCache, PteroDum, PteroOdd, and PteroEffigy. These tools support initial access, persistence, document theft, in-memory payload execution, lateral movement, and propagation via removable and network drives. Gamaredon has also used commodity or publicly available tooling, including remote administration and reverse-shell frameworks, adapting them for espionage operations. Tradecraft associated with Gamaredon includes spearphishing, malicious macro execution, HTML smuggling, scheduled-task persistence, Startup-folder persistence, Registry Run-key persistence, weakening Microsoft Office macro security settings through registry modification, removable-media discovery, USB-assisted propagation, system information discovery, and document exfiltration. The group has been observed gathering host identifiers and drive information, scanning removable drives, and using weaponized LNK files and installer replacement techniques to spread within targeted environments. A defining feature of Gamaredon’s more recent operations is extensive abuse of legitimate and third-party services to conceal infrastructure and improve resilience. The actor has used cloud storage, dead-drop resolvers, tunneling services, serverless worker platforms, messaging and publishing services, and social-media-like platforms for command-and-control discovery, payload retrieval, and exfiltration. This reliance on legitimate services complicates blocking and takedown efforts and reflects an evolution toward more flexible, layered infrastructure. Gamaredon remained highly active through 2025, when it reportedly conducted dozens of distinct spearphishing campaigns, most in the second half of the year, primarily against Ukrainian governmental and military institutions. Reporting also describes continued malware development, including new PowerShell-based tooling and exploitation of CVE-2025-8088 in some campaigns to gain persistence. The group’s sustained focus on Ukrainian targets, alignment with Russian state interests, and long-running role as an access and espionage actor make it one of the most persistent Russian cyber threats in the Russia-Ukraine conflict.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
37 malware families attributed to this actor across reporting.
32 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The June 2026 WinRAR reporting shows SHADOW-EARTH-066/UAC-0226 and Earth Dahu/Gamaredon continuing to exploit CVE-2025-8088 against Ukrainian organizations nearly a year after patch release, using the flaw for credential theft, cookie theft, file theft, and espionage staging.
Indicators of Compromise (IoCs):- ... CVE-2025-6218 WinRAR vulnerability used by Gamaredon/Sandworm/RomCom
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Документи ... містили шкідливий код для експлуатації відомої вразливості «Microsoft Office» CVE-2017-0199 ... що надає змогу зловмиснику виконати довільний код на пристрої користувача, при відкритті інфікованого файлу.
Interestingly, the SSU documented Gamaredon leveraging this same TTP as early as 2018 exploiting CVE-2018-20250.
292 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FSB-linked Russian group conducting large-scale attacks against Ukrainian government institutions.
Conducts high-volume regional espionage against Ukrainian government, military, security, and critical-sector organizations with emphasis on persistence, repeated re-entry, and operational intelligence collection.
Used a malware suite for persistence, physical propagation, and document theft while abusing legitimate services and cloud infrastructure.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.