Gamaredon, also tracked as Blue Otso, is a Russian state-linked cyber espionage threat actor associated with operations against Ukrainian entities. The group has been linked to Russia's FSB, specifically Centre 18 in Crimea, and has been active in campaigns aligned with Russian intelligence interests. Reported activity includes targeting organizations in eastern Ukraine in the period leading up to the public identification of alleged operators by the Security Service of Ukraine in November 2021. Gamaredon is primarily an espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.