Gamaredon Group — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    Gamaredon Group

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    Gamaredon Group
    🔱
    Regional focus emblem (illustrative)
    Also known asShuckworm · Armageddon · Primitive Bear · Trident Ursa · ACTINIUM · Iron Tilden
    Formationc. 2013
    TypeAdvanced persistent threat (state-sponsored)
    PurposeEspionage, Information theft, Surveillance
    Target SectorsGovernment (Ukraine), Military, Law Enforcement
    Alleged parent org.FSB (Crimea-based Center 18)
    Attribution confidenceHigh
    Status● Highly Active
    Notable toolsPterodo, Giddome, UltraVNC, PowerShell scripts

    Gamaredon Group, also known as Shuckworm and Armageddon, is a prolific Russian state-sponsored threat actor focused almost exclusively on Ukrainian national security interests. Publicly attributed by the Security Service of Ukraine (SBU) to the FSB Office in the Republic of Crimea and the City of Sevastopol, the group has been active since the 2013 annexation of Crimea.[1]

    Unlike Turla or APT28, Gamaredon is characterized by a “quantity over quality” approach. They utilize high-volume phishing campaigns and rapidly iterated, relatively low-sophistication malware to maintain a constant presence in Ukrainian government and military networks.[2]

    Aliases used by other vendors:
    Shuckworm (Symantec) · Armageddon (SBU/Ukraine) · Primitive Bear (CrowdStrike) · Trident Ursa (Unit 42) · ACTINIUM (Microsoft) · Iron Tilden (Secureworks)

    Overview

    Gamaredon serves as a tactical cyber-espionage unit for the FSB, prioritizing the theft of military plans, diplomatic communications, and law enforcement data. They are known for their extreme persistence; if one of their implants is discovered and removed, they often attempt to re-infect the same target within hours using slightly modified payloads.[1]

    Attribution

    In November 2021, the Security Service of Ukraine (SBU) formally identified five members of the group, linking them directly to the FSB’s “Center 18” in Crimea. Technical analysis of their C2 infrastructure and phishing lures consistently aligns with Russian geopolitical interests in the Donbas and Crimean regions.[3]

    “Gamaredon is an ‘aggressive and fast’ actor. They do not care about being caught; they care about how quickly they can get back in after being kicked out.”
    — Ukrainian Cybersecurity Report, 2023[4]

    Targets and Geopolitics

    • Ukrainian Armed Forces — Operational data and troop movements.
    • Government Agencies — Ministries, regional administrations, and emergency services.
    • Humanitarian Organizations — NGOs operating within conflict zones in Ukraine.

    Operational History

    PeriodKey Activity
    2013–2014Initial formation during the Euromaidan protests and Crimea annexation.
    2017–2021Massive expansion of phishing infrastructure; daily targeting of Ukrainian officials.
    2022–PresentActive support of the Russian invasion through persistent tactical espionage and data theft.

    Toolset and Malware

    The group relies heavily on custom scripts (VBScript, PowerShell) and open-source tools, which allows them to bypass traditional antivirus through constant minor variations in code.

    NameFunction
    Pterodo (Pteranodon)A modular backdoor used for reconnaissance and secondary payload delivery.
    GiddomeA custom backdoor with data exfiltration and credential theft capabilities.
    UltraVNCOpen-source remote access software used to manually control infected machines.
    TelekopyeTelegram-based bots used for automated data exfiltration.

    Tactics and Procedures

    TacticTechniqueDetails
    Initial AccessPhishingDocuments referencing military orders or regional conflict updates.
    ExecutionMacrosHeavy use of malicious VBA macros in .docx and .template files.
    PersistenceScheduled TasksSetting scripts to run every few minutes to ensure connection to C2.
    C2Dynamic DNSFrequent use of No-IP and other DDNS services to mask infrastructure.

    References

    1. Security Service of Ukraine (SBU), “Identification of FSB Officers in Crimea” (2021).
    2. Unit 42 by Palo Alto Networks, “Trident Ursa: The Most Active APT Targeting Ukraine” (2022).
    3. Symantec Enterprise, “Shuckworm: Continual Attacks on Ukraine” (2023).
    4. Microsoft Threat Intelligence Center (MSTIC), “ACTINIUM: Targetting Ukrainian Organizations” (2022).
    Categories: Advanced persistent threats · Russian state-sponsored hacking · FSB · Ukraine Conflict · Cyber-espionage
    This page was last synced August 2026. Content reflects ongoing tactical monitoring.