> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
GAMAREDON
/actor/gamaredon/ · 0 intel reports
Gamaredon is a Russian state-sponsored threat actor attributed to the FSB's Crimea-based cyber unit, distinguished by the extraordinary volume and persistence of its operations almost exclusively targeting Ukrainian government, military, law enforcement, and critical infrastructure organisations. Unlike most APT groups that conduct careful, targeted operations to maintain stealth, Gamaredon operates at an industrial scale , conducting thousands of phishing attacks weekly and prioritising persistence and volume over operational security, reflecting a mandate for sustained harassment and intelligence collection rather than careful long-term espionage.
Gamaredon's prolific targeting of Ukraine has intensified dramatically since Russia's full-scale invasion in February 2022, with the group reportedly conducting near-daily operations against Ukrainian government ministries, military communications infrastructure, and law enforcement databases. Their ability to sustain this operational tempo while maintaining access to active conflict zone targets makes them one of the most operationally active APT groups globally by attack frequency.
The group's malware arsenal includes custom-developed tools such as Pterodo/Pteranodon backdoors, GammaLoad, GammaSteel, and various PowerShell-based stagers. Gamaredon is notable for using Microsoft Word template injection , embedding malicious remote templates in phishing documents that download additional payloads when opened, even on systems with macros disabled. USB worm capabilities enable spread to network-isolated systems, critical for targeting Ukrainian military field equipment.
Ukraine's Security Service (SBU) publicly identified five specific FSB officers responsible for Gamaredon operations in 2021, providing unprecedented naming of the individuals behind a foreign state cyber espionage programme. Despite this exposure, operations continued unabated , a demonstration of Russia's calculated indifference to attribution when conducting operations against Ukraine, which it does not recognise as having the sovereign right to impose consequences for Russian state actions.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Gamaredon requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.