Gamaredon Group is a Russian state-linked cyber-espionage intrusion set attributed by Ukrainian authorities to the Russian Federal Security Service (FSB), including its Crimean branch and FSB Center 18. Active since at least 2013, the group is primarily focused on Ukrainian government, security, defense, law-enforcement, and other state-linked organizations, and has also targeted European Union state institutions. It is widely tracked as Armageddon, Shuckworm, Primitive Bear, ACTINIUM, Trident Ursa, BlueAlpha, Aqua Blizzard, APT-C-53, and UAC-0010. The group commonly obtains access through spearphishing, malicious attachments, spoofed messages, and document- or archive-based lures. Its operations use multi-stage malware delivery, including Pterodo/Pteranodon, GammaLoad, GammaDrop, GammaWorm, GammaSteel, QuietSieve, DilongTrash, DinoTrain, and PteroLNK. Reported tradecraft includes HTML smuggling, execution through signed Windows utilities, PowerShell staging, hidden execution, dead-drop resolvers, and Telegram-supported delivery or command-and-control mechanisms. Gamaredon has also been reported exploiting CVE-2025-8088 to establish execution and persistence on Ukrainian victim systems. Gamaredon maintains persistence through scheduled tasks, startup execution, registry modifications, and alternate data streams. It conducts host, account, file, and process discovery; collects screenshots and documents; retrieves additional payloads; propagates through removable media and network shares; and exfiltrates collected data through cloud storage or command-and-control infrastructure. The group has weakened Office macro security, compiled downloader source code directly on compromised systems, and used concealed PowerShell and console execution to reduce user visibility. Its operational objective is cyberintelligence collection in support of Russian interests, particularly against Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
48 malware families attributed to this actor across reporting.
43 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Gamaredon and UAC-0226 are actively exploiting CVE-2025-8088, a CVSS 8.8 WinRAR path traversal flaw, to place malicious payloads outside the intended RAR extraction directory, including in the Windows Startup folder.
Indicators of Compromise (IoCs):- ... CVE-2025-6218 WinRAR vulnerability used by Gamaredon/Sandworm/RomCom
Analysts assess that Culver Aviation (a Ukrainian aviation company) probably has been targeted by multiple phishing lures containing malicious Word documents that use the CVE-2017-0199 vulnerability, which is exploited to execute the malware on victim systems through specially crafted Word documents. The Malicious Word document leverages the exploit CVE-2017-0199 to download and execute remote templates as a second stage of the malware. This exploit can be triggered by opening the Word document without any macro involvement.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Interestingly, the SSU documented Gamaredon leveraging this same TTP as early as 2018 exploiting CVE-2018-20250.
800 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gamaredon Group appears only in the detection's annotations list.
Mentioned as a comparative example of possible collaboration with Turla, where Gamaredon-attributed malware reportedly deployed Kazuar.
Russian state-linked threat actor mentioned as part of persistent campaigns targeting Ukraine in the lead-up to and during the broader conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.