The Russia-linked Gamaredon threat group, also tracked as ACTINIUM, Primitive Bear, Shuckworm, and Aqua Blizzard, has been tied to sustained spearphishing operations against Ukrainian government and state institutions. Reporting describes lure documents delivered through spoofed or compromised email accounts, with infection chains using remote template injection, VBA macros, and malware components including GammaDrop, GammaLoadIdentifier, and the custom backdoor Pteranodon. Researchers said the activity remained ongoing across multiple waves and was aimed at gaining initial access and maintaining footholds inside targeted environments.
Technical analysis linked the campaign to abuse of CVE-2025-8088, startup-folder VBScript persistence, changes to Microsoft Word macro security registry settings, host identifier collection, and HTTP-based command-and-control communications over dynamic DNS-hosted infrastructure. Separate infrastructure research expanded on previously reported Gamaredon/ACTINIUM network assets by using passive DNS pivots, identifying domain and subdomain patterns, shared IP reuse, and additional likely attacker-controlled .ru domains consistent with the group’s broader operational infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
HarfangLab said the Gamaredon spearphishing campaign targeting Ukrainian state institutions dated back to September 2025. The activity involved spoofed or compromised-email delivery and the GammaDrop and GammaLoadIdentifier infection chain.
Embee Research noted that many domains from Microsoft's ACTINIUM reporting resolved to IP address 139.180.174[.]234 on 2022-07-27. This shared resolution became the basis for later passive DNS pivoting.
Elastic documented a spearphishing email dated January 17, 2020 that targeted the National Security and Defense Council of Ukraine. The lure impersonated official Ukrainian government correspondence and used remote template injection.
Metadata cited by Elastic showed the malicious remote template was created on December 12, 2019 and modified on December 24, 2019. The template was later reused across multiple phishing campaigns.
Elastic said the first sample leveraging the identified Gamaredon domain was submitted to VirusTotal in early September 2019. This provides an early public artifact tied to the campaign infrastructure.
Elastic Security reported that the earliest identified infrastructure associated with the Gamaredon campaign dated to August 2019. This marks the earliest explicit anchor for the activity described in the references.
HarfangLab investigated an active Gamaredon spearphishing campaign and linked it to abuse of CVE-2025-8088. The report identified roughly a dozen phishing waves against Ukrainian state institutions and said the campaign was still ongoing at the time of reporting.
Embee Research published an analysis expanding Microsoft's 2022 ACTINIUM infrastructure reporting by pivoting on passive DNS data. The method produced 159 unique .ru domains and suggested 122 additional candidate domains likely related to the actor, though some may be false positives.
Elastic Security described an ongoing campaign attributed with moderate confidence to Gamaredon that targeted Ukrainian government officials and departments. The report detailed spearphishing, remote template injection, VBA macros, VBScript persistence, and links to updated Pteranodon-related artifacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
harfanglab.io
Open sourceharfanglab.io
Open sourceharfanglab.io
Open sourceembee-research.ghost.io
Open sourceelastic.co
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.