🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
GAMAREDON

/actor/gamaredon/  ·  0 intel reports

Year Established
2013
Attribution
Russia (FSB)
Motivation
Espionage, Sabotage (Ukraine-focused)
Modus Operandi (MO)
Massive-scale Ukraine targeting, phishing, USB worms, template injection, near-daily attack operations
Primary Aliases
Primitive Bear, Shuckworm, Actinium, Armageddon, UAC-0010

Gamaredon is a Russian state-sponsored threat actor attributed to the FSB's Crimea-based cyber unit, distinguished by the extraordinary volume and persistence of its operations almost exclusively targeting Ukrainian government, military, law enforcement, and critical infrastructure organisations. Unlike most APT groups that conduct careful, targeted operations to maintain stealth, Gamaredon operates at an industrial scale , conducting thousands of phishing attacks weekly and prioritising persistence and volume over operational security, reflecting a mandate for sustained harassment and intelligence collection rather than careful long-term espionage.

Gamaredon's prolific targeting of Ukraine has intensified dramatically since Russia's full-scale invasion in February 2022, with the group reportedly conducting near-daily operations against Ukrainian government ministries, military communications infrastructure, and law enforcement databases. Their ability to sustain this operational tempo while maintaining access to active conflict zone targets makes them one of the most operationally active APT groups globally by attack frequency.

The group's malware arsenal includes custom-developed tools such as Pterodo/Pteranodon backdoors, GammaLoad, GammaSteel, and various PowerShell-based stagers. Gamaredon is notable for using Microsoft Word template injection , embedding malicious remote templates in phishing documents that download additional payloads when opened, even on systems with macros disabled. USB worm capabilities enable spread to network-isolated systems, critical for targeting Ukrainian military field equipment.

Ukraine's Security Service (SBU) publicly identified five specific FSB officers responsible for Gamaredon operations in 2021, providing unprecedented naming of the individuals behind a foreign state cyber espionage programme. Despite this exposure, operations continued unabated , a demonstration of Russia's calculated indifference to attribution when conducting operations against Ukraine, which it does not recognise as having the sovereign right to impose consequences for Russian state actions.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Gamaredon requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles