Giddome is a Windows backdoor and information-stealing malware family associated with the Russia-linked espionage group Shuckworm, also known as Gamaredon or Armageddon. It has been used in campaigns targeting Ukrainian government, military, security, research, and related organizations as part of long-running intelligence collection operations.
Observed intrusion chains delivering Giddome relied on spearphishing and malicious archives or Office document lures, followed by script-based execution using components such as PowerShell, VBScript, LNK files, and mshta. In some campaigns, Giddome was deployed alongside other Gamaredon tooling including Pterodo, and operators also used removable media propagation in broader operations to spread malware within victim environments.
Giddome has been described both as a backdoor and as an infostealer. Reported functionality includes theft and exfiltration of files and host data, collection of screenshots, and the ability to download and execute additional payloads. Related Gamaredon implants suspected to belong to the same family searched local, removable, and remote drives for documents and archives of intelligence value, tracked previously stolen files, and transmitted collected data to command-and-control infrastructure. The malware’s role in operations was to support persistent espionage and follow-on access inside compromised Ukrainian networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Symantec also saw what was likely Giddome, an infostealer tool that is a known Shuckworm backdoor, deployed onto victim networks to steal and exfiltrate data of interest.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
In this recent activity, we also observed the group leveraging legitimate services to act as C&C servers, including using the Telegram messaging service for its C&C infrastructure. More recently, they have also used Telegram’s micro-blogging platform, called Telegraph, to store C&C addresses.
233 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer/backdoor associated with Shuckworm and used to steal and exfiltrate data from victim networks.
A backdoor delivered in some Gamaredon intrusions alongside GammaLoad.
Referenced as a suspected backdoor family that may encompass the newly observed infostealer, though the article says this could not be confirmed.
A Shuckworm-associated backdoor delivered via suspicious 'ntuser' themed files; observed variants support persistent malicious execution on victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.