Russia-linked Gamaredon—also tracked as Shuckworm, Primitive Bear, Trident Ursa, and STEADY#URSA—conducted sustained cyber-espionage operations against Ukrainian government, military, and other public- and private-sector organizations, while also probing at least one petroleum refining company in a NATO member state. Researchers reported a sharp rise in email-borne attacks tied to the group, including a late-2022 surge against gov.ua subdomains and broader targeting of energy, media, financial, business, and non-profit entities. The actor increasingly used both Ukrainian- and English-language lures delivered through spearphishing emails, malicious attachments, phishing pages, and archive files to gain initial access and support intelligence collection.
Across multiple campaigns, Gamaredon deployed evolving malware chains that included the Pteranodon backdoor, the SUBTLE-PAWS PowerShell backdoor, and at least eight additional custom payloads, alongside legitimate tools such as UltraVNC and Process Explorer. Intrusions used macro-enabled Word documents, remote template injection, .lnk shortcut files, VBS droppers, scheduled tasks, startup-folder persistence, registry Run keys, and repeated HTTP/HTTPS command-and-control callbacks, with some infrastructure hosted through Dynamic DNS, Telegraph pages, DNS-based retrieval, and network space linked to AS9123 TimeWeb Ltd. Researchers also observed USB propagation behavior, exploitation attempts for CVE-2021-3438, and suspicious msiexec activity, underscoring the group’s continued adaptation of tradecraft for long-term access and espionage in support of Russia’s war-related objectives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Trellix observed a 20-fold increase in email-based cyberattacks targeting Ukraine's public and private sectors beginning in the third week of November 2022 and staying high through the end of December.
Trellix observed an abnormally large number of detections in Ukraine from October 2022 to January 2023 tied to a fake Adobe software activation tool that installed a backdoor.
Symantec reported that Shuckworm activity targeting Ukrainian organizations began on July 15, 2022 and was still ongoing as of August 8, 2022. The campaign used likely email-delivered 7-Zip archives, mshta-based retrieval from xsph.ru infrastructure, and payloads including PowerShell stealers, Backdoor.Pterodo, Giddome, a 4896.exe surveillance backdoor, and remote access tools Ammyy Admin and AnyDesk.
The Record reported that on February 26 an individual apparently tied to Trident Ursa posted Kyiv-based researcher Mikhail Kasimov's personal details online along with a threat.
On February 24, 2022, an individual apparently tied to Trident Ursa, using the account @Anton15001398, threatened Ukraine-based researcher Mikhail Kasimov on Twitter and also messaged other research groups. Unit 42 said the activity began immediately after Russia's invasion of Ukraine and appeared intended to intimidate defenders tracking the group.
Trellix said that since February 2022, cyberattacks against Ukraine have disrupted access to basic services and undermined distribution of medicines, food, and relief supplies.
Elastic identified a spearphishing email dated January 17, 2020 that targeted the National Security and Defense Council of Ukraine using Gamaredon-linked tradecraft.
Elastic said the same remote template was modified on December 24, 2019, indicating continued preparation of the phishing tooling.
Metadata cited by Elastic showed a malicious remote template later reused in campaigns was created on December 12, 2019.
Elastic reported that the first sample leveraging the identified Dynamic DNS domain was submitted to VirusTotal in early September 2019.
Elastic Security said the earliest identified infrastructure associated with the tracked Gamaredon campaign dated to August 2019.
EclecticIQ identified Gamaredon-attributed phishing activity targeting the Security Service of Ukraine and, in English- and Latvian-language lures, the Latvian Ministry of Defence and likely other NATO allies. The campaign used TAR/LNK delivery, HTML smuggling, and MSHTA.exe to fetch second-stage HTA malware, with infrastructure overlaps tying it to prior Gamaredon operations.
Unit 42 found that Trident Ursa, also known as Gamaredon, unsuccessfully attempted to compromise a large petroleum refining company in a NATO member nation on August 30.
Elastic described a campaign it tracked for several months targeting Ukrainian government officials and departments with remote template injection, VBA macros, VBScript persistence, and Dynamic DNS infrastructure.
Symantec said the monitored attacks began in July with spearphishing emails carrying macro-enabled Word documents that launched a multi-stage infection chain against Ukrainian entities.
Securonix reported an ongoing campaign likely related to Shuckworm that targeted Ukrainian military personnel and used a newly tracked PowerShell backdoor named SUBTLE-PAWS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcemandiant.com
Open sourceunit42.paloaltonetworks.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcesecuronix.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcessu.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.