NEW: Group Profiler — instant APT intel lookup. Try it →

Gamaredon Group

G0047 Russia MITRE ATT&CK →

Also known as: IRON TILDEN · Primitive Bear · ACTINIUM · Armageddon · Shuckworm · DEV-0157 · Aqua Blizzard · NastyShrew

Overview

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.

Naming & attribution

Gamaredon Group is tracked under 9 names across the industry. It uses 70 documented ATT&CK techniques — more than 94% of the 174 groups tracked here. Activity attributed since at least 2013.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
IRON TILDENSecureworks CTU
Primitive BearUnit 42
ACTINIUMMicrosoft Threat Intelligence Center
ArmageddonSymantec
ShuckwormSymantec
DEV-0157Microsoft Threat Intelligence Center
Aqua BlizzardMicrosoft
NastyShrewCloudflare
Gamaredon GroupKasza, A. and Reichel, D

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1001 Data Obfuscation — used by 1 of 174 groups
  • T1102.003 One-Way Communication — used by 2 of 174 groups
  • T1137 Office Application Startup — used by 2 of 174 groups
  • T1027.012 LNK Icon Smuggling — used by 3 of 174 groups
  • T1491.001 Internal Defacement — used by 3 of 174 groups
  • T1561.001 Disk Content Wipe — used by 3 of 174 groups
  • T1568.001 Fast Flux DNS — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • MuddyWater Iran — 33 shared techniques (31% overlap)
  • Kimsuky North Korea — 45 shared techniques (29% overlap)
  • FIN7 — 31 shared techniques (29% overlap)
  • TA2541 — 22 shared techniques (29% overlap)
  • APT32 Vietnam — 32 shared techniques (28% overlap)
  • Mustang Panda China — 31 shared techniques (25% overlap)

Malware families with current indicators

One family attributed to Gamaredon Group, carrying 2,964 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Remcos 2,964 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Government

Regions

Germany · Ukraine

Capabilities

  • Destructive / data-wiping operations — ATT&CK T1561.001
  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 70 techniques across 12 tactics

Resource Development

Initial Access

Execution

Defense Impairment

Impact

Tools & malware (6)

QuietSieve · Pteranodon · Remcos · Ping · Reg · PowerPunch

Reporting (3)