Gamaredon Group
Gamaredon is a Russia-linked, state-sponsored cyberespionage threat actor officially linked in the provided reporting to Russia’s Federal Security Service (FSB). The group has been active since at least 2013/2014 and is consistently described as focusing primarily on Ukraine. Reported targets include Ukrainian government, military, critical infrastructure, law enforcement, journalists, NGOs, and other national security-related organizations. Known aliases in the provided content include Actinium, APT-C-53, Aqua Blizzard, Armageddon, DEV-0157, Gamaredon, Iron Tilden, Primitive Bear, SectorC08, Shuckworm, Trident Ursa, UNC530, UAC-0010, BlueAlpha, and ACTINUM. The content also notes that SBU publicly associated Callisto/Calisto with Gamaredon, but that this link is not supported by other security companies or researchers. The group is described as specializing in long-term, persistent intrusion and espionage operations against Ukraine, with heavy use of spear-phishing and malicious attachments, including booby-trapped RAR archives. Recent reporting in the provided content describes exploitation of the WinRAR path traversal vulnerability CVE-2025-8088 to deliver a modular malware chain. Sekoia grouped this tooling under a "Gamma" taxonomy including GammaPhish, GammaLoad, GammaWorm, GammaSteel, and GammaWipe/GamaWiper. In that chain, weaponized XHTML lures and HTML smuggling delivered malicious RAR archives that placed an HTA file in the Windows Startup folder, leading to execution via mshta.exe. GammaLoad was described as a VBScript staging component used to fingerprint hosts, update registry-based network configuration through dead-drop resolvers, and fetch arbitrary VBScript payloads from command-and-control servers. GammaWorm was described as a heavily obfuscated VBScript worm that stores modules in NTFS Alternate Data Streams, persists via RunOnce registry keys and scheduled tasks, and propagates through USB drives and network shares by hiding legitimate folders and replacing them with malicious LNK shortcuts. The group’s infrastructure resolution and C2 concealment techniques include use of Telegram channels, Telegra.ph, graph.org, Teletype, Cloudflare Workers, public third-party websites, ngrok, TXT records, and cloud storage. GammaSteel was described as a modular information stealer that collects targeted files and exfiltrates them to AWS S3 or other actor-controlled servers. Additional behaviors directly mentioned in the content include use of obfuscated PowerShell scripts for staging, batch scripts for C2 establishment and payload download, registry Run keys for persistence, process enumeration including Process Explorer, file collection and upload to C2, removable-drive scanning, and deletion of files used during operations. The content also states that ESET presented technical evidence in 2025 that Gamaredon facilitated Turla access to high-value Ukrainian targets. In incidents observed between February and June 2025, Gamaredon tooling including PteroGraphin and PteroOdd was used to deploy Turla’s Kazuar backdoor, and in at least one case Gamaredon restored Turla’s access after Turla appeared to lose its foothold. The reporting characterizes this as direct operational collaboration and a division of labor in which Gamaredon establishes or maintains access while Turla deploys a more advanced espionage platform.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇺🇦 Ukraine
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
41 malware families attributed to this actor across reporting.
36 additional families tracked in Mallory.
Associated vulnerabilities
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits CVE-2025-8088, a critical path traversal flaw in WinRAR patched in version 7.13.
Indicators of Compromise (IoCs):- ... CVE-2025-6218 WinRAR vulnerability used by Gamaredon/Sandworm/RomCom
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Документи ... містили шкідливий код для експлуатації відомої вразливості «Microsoft Office» CVE-2017-0199 ... що надає змогу зловмиснику виконати довільний код на пристрої користувача, при відкритті інфікованого файлу.
Interestingly, the SSU documented Gamaredon leveraging this same TTP as early as 2018 exploiting CVE-2018-20250.
Observables
204 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage activity focused on Ukrainian targets using a modular, nearly fileless infection chain that exploits a WinRAR vulnerability for initial access, stages payloads with VBScript loaders, propagates via USB drives and network shares, and supports data theft and destructive capabilities.
Conducting espionage-oriented intrusions against Ukraine by exploiting a WinRAR vulnerability and deploying multiple malware families for host fingerprinting, persistence, propagation, data theft, and potentially destructive actions.
Russian state-sponsored espionage activity exploiting a WinRAR path traversal flaw to deliver GammaPhish, GammaLoad, GammaWorm, GammaSteel, and potentially GammaWipe for host fingerprinting, persistence, propagation, and data theft, primarily against Ukrainian targets.
An active espionage group targeting Ukraine that uses spearphishing, lightweight custom tooling, and rapid operations to compromise military and government organizations, and in 2025 facilitated Turla’s access to already compromised Ukrainian targets.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.