{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "gamaredon",
    "slug": "gamaredon",
    "name": "Gamaredon",
    "shortName": "Gamaredon",
    "country": "Russia",
    "countryCode": "RU",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2013",
    "prominence": 82,
    "mitreGroupId": "G0047",
    "malpediaSlug": "gamaredon_group",
    "tagline": "FSB officers operating from occupied Crimea, publicly named by Ukraine's security service. Enormous volume, minimal sophistication, relentlessly focused on Ukraine.",
    "bio": "Gamaredon is the loudest state actor in operation, and deliberately so. It runs enormous volumes of phishing against Ukrainian government, military, and law enforcement targets with tooling that is by any technical measure unsophisticated — VBScript droppers, self-modifying batch files, and rapid domain churn through free dynamic-DNS providers.\n\nThat crudeness is a strategy, not a shortcoming. The group operates on the assumption that most of its infrastructure will be burned within days, so it rotates C2 domains constantly and re-infects the same organisations repeatedly. Defenders describe fighting Gamaredon as an endless cleanup rather than a discrete incident.\n\nIn November 2021 Ukraine's Security Service (SSU) published an unusually detailed exposure: it named five FSB officers by name, identified them as serving in the FSB's Crimean directorate, and released intercepted communications. Several of the named individuals were Ukrainian SBU officers who defected to Russian service following the 2014 annexation of Crimea.\n\nIts practical significance is as a scouting layer. CERT-UA and ESET have both documented more capable Russian services — including Turla — deploying implants onto hosts that Gamaredon compromised first, effectively treating the group's mass access as a target-selection pipeline.",
    "attribution": {
      "sponsor": "Russia",
      "service": "FSB — Federal Security Service",
      "unit": "18th Centre / Crimean directorate",
      "unitDetail": "FSB Office in the Republic of Crimea and Sevastopol",
      "confidence": "confirmed",
      "summary": "Ukraine's Security Service publicly identified five FSB officers by name in November 2021, attributing Gamaredon to the FSB's directorate in occupied Crimea and releasing intercepted communications as supporting evidence. Several named individuals were former SBU officers who defected after the 2014 annexation. CERT-UA tracks the activity as UAC-0010, and the attribution is corroborated by ESET and Unit 42 reporting.",
      "sources": [
        {
          "org": "Security Service of Ukraine (SSU)",
          "title": "SSU identifies FSB hackers behind more than 5,000 cyberattacks on Ukraine",
          "url": "https://ssu.gov.ua/en/novyny/sbu-vstanovyla-khakeriv-fsb-yaki-zdiisnyly-ponad-5-tys-kiberatak-na-derzhavni-orhany-ukrainy",
          "date": "2021-11-04"
        },
        {
          "org": "Unit 42",
          "title": "Trident Ursa (Gamaredon) APT Cyber Conflict Operations Unwavering Since Invasion",
          "url": "https://unit42.paloaltonetworks.com/trident-ursa/",
          "date": "2022-12-20"
        }
      ]
    },
    "motivations": [
      "espionage"
    ],
    "targetSectors": [
      "Government",
      "Defense",
      "Critical Infrastructure",
      "Media & Journalism",
      "Education",
      "NGO & Civil Society"
    ],
    "targetCountries": [
      "Ukraine",
      "Latvia",
      "Lithuania",
      "Poland",
      "Bulgaria",
      "Georgia"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Gamaredon Group",
        "url": "https://attack.mitre.org/groups/G0047/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Aqua Blizzard",
        "correlation": "exact",
        "note": "Formerly ACTINIUM"
      },
      {
        "org": "microsoft",
        "name": "ACTINIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Primitive Bear",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Trident Ursa",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "IRON TILDEN",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "BlueAlpha",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Shuckworm",
        "correlation": "exact"
      },
      {
        "org": "eset",
        "name": "Gamaredon",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Armageddon",
        "correlation": "exact",
        "note": "Also the group's self-styled name, from which 'Gamaredon' is an anagrammatic derivation"
      },
      {
        "org": "mandiant",
        "name": "UNC530",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "Pterodo / Pteranodon",
        "type": "backdoor",
        "custom": true,
        "description": "The group's flagship implant family, continuously rewritten in VBScript, C#, and compiled variants to defeat signatures.",
        "malpediaSlug": "win.pteranodon"
      },
      {
        "name": "GammaLoad",
        "type": "loader",
        "custom": true,
        "description": "VBScript downloader retrieving further stages from rapidly rotating dynamic-DNS domains."
      },
      {
        "name": "GammaSteel",
        "type": "utility",
        "custom": true,
        "description": "PowerShell exfiltration script harvesting documents by extension from local and removable drives."
      },
      {
        "name": "LitterDrifter",
        "type": "malware",
        "custom": true,
        "description": "USB-propagating worm that spreads to removable media, producing incidental infections well beyond the intended target set."
      },
      {
        "name": "PowerPunch",
        "type": "loader",
        "custom": true,
        "description": "PowerShell downloader that keys its payload decryption to the target host, frustrating sandbox analysis."
      },
      {
        "name": "Remote template injection",
        "type": "utility",
        "custom": false,
        "description": "Office documents that fetch a weaponised template only when opened by the intended victim."
      }
    ],
    "techniques": [
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access",
        "note": "Very high volume, Ukrainian-language government-themed lures"
      },
      {
        "tCode": "T1221",
        "name": "Template Injection",
        "tactic": "Defense Evasion",
        "note": "Remote template fetch on document open"
      },
      {
        "tCode": "T1091",
        "name": "Replication Through Removable Media",
        "tactic": "Lateral Movement",
        "note": "LitterDrifter USB worm"
      },
      {
        "tCode": "T1059.005",
        "name": "Command and Scripting Interpreter: Visual Basic",
        "tactic": "Execution"
      },
      {
        "tCode": "T1059.001",
        "name": "Command and Scripting Interpreter: PowerShell",
        "tactic": "Execution"
      },
      {
        "tCode": "T1547.001",
        "name": "Boot or Logon Autostart Execution: Registry Run Keys",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1053.005",
        "name": "Scheduled Task/Job: Scheduled Task",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1568.001",
        "name": "Dynamic Resolution: Fast Flux DNS",
        "tactic": "Command and Control",
        "note": "Heavy use of free dynamic-DNS providers with sub-daily rotation"
      },
      {
        "tCode": "T1102",
        "name": "Web Service",
        "tactic": "Command and Control",
        "note": "Telegram channels used as dead drops for C2 addresses"
      },
      {
        "tCode": "T1005",
        "name": "Data from Local System",
        "tactic": "Collection"
      },
      {
        "tCode": "T1113",
        "name": "Screen Capture",
        "tactic": "Collection"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2017-0199",
        "firstExploited": "2018-03-01",
        "usage": "OLE2link RTF exploit in Ukrainian-language lure documents delivering Pterodo.",
        "source": {
          "org": "ESET",
          "title": "Gamaredon group grows its game",
          "url": "https://www.welivesecurity.com/2020/06/11/gamaredon-group-grows-its-game/",
          "date": "2020-06-11"
        }
      },
      {
        "cveId": "CVE-2017-11882",
        "firstExploited": "2018-06-01",
        "usage": "Equation Editor overflow in phishing documents against Ukrainian government targets.",
        "source": {
          "org": "Unit 42",
          "title": "Trident Ursa APT Cyber Conflict Operations",
          "url": "https://unit42.paloaltonetworks.com/trident-ursa/",
          "date": "2022-12-20"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "turla",
        "type": "supplier",
        "confidence": "high",
        "note": "ESET documented Turla deploying its own implants onto hosts Gamaredon had already compromised — the noisy group functioning as a target-selection layer for the sophisticated one."
      },
      {
        "relatedActorId": "sandworm",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "Frequently present in the same Ukrainian victim networks; different services with distinct objectives."
      },
      {
        "relatedActorId": "apt28",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both Russian state services targeting Ukraine; FSB and GRU respectively."
      }
    ],
    "reports": [
      {
        "org": "Security Service of Ukraine",
        "title": "SSU names five FSB officers behind Gamaredon operations",
        "url": "https://ssu.gov.ua/en/novyny/sbu-vstanovyla-khakeriv-fsb-yaki-zdiisnyly-ponad-5-tys-kiberatak-na-derzhavni-orhany-ukrainy",
        "date": "2021-11-04"
      },
      {
        "org": "ESET",
        "title": "Gamaredon group grows its game",
        "url": "https://www.welivesecurity.com/2020/06/11/gamaredon-group-grows-its-game/",
        "date": "2020-06-11"
      },
      {
        "org": "Check Point Research",
        "title": "Malware Spotlight: Into the Trash — Analyzing LitterDrifter",
        "url": "https://research.checkpoint.com/2023/malware-spotlight-into-the-trash-analyzing-litterdrifter/",
        "date": "2023-11-16"
      },
      {
        "org": "Microsoft Threat Intelligence",
        "title": "ACTINIUM targets Ukrainian organizations",
        "url": "https://www.microsoft.com/en-us/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/",
        "date": "2022-02-04"
      }
    ],
    "campaigns": [
      {
        "id": "gamaredon-ukraine",
        "actorId": "gamaredon",
        "name": "Sustained Ukrainian Government Targeting",
        "date": "2014-03-01",
        "significance": "major",
        "targetSectors": [
          "Government",
          "Defense",
          "Critical Infrastructure",
          "Media & Journalism"
        ],
        "targetCountries": [
          "Ukraine"
        ],
        "cveIds": [
          "CVE-2017-0199",
          "CVE-2017-11882"
        ],
        "summary": "Continuous high-volume phishing against Ukrainian government, military, and law enforcement since the annexation of Crimea, with more than 5,000 attacks attributed by Ukraine's Security Service. Deliberately noisy and constantly rebuilt, functioning in practice as a scouting layer for more capable Russian services.",
        "sources": [
          {
            "org": "Security Service of Ukraine",
            "title": "SSU identifies FSB hackers behind more than 5,000 cyberattacks",
            "url": "https://ssu.gov.ua/en/novyny/sbu-vstanovyla-khakeriv-fsb-yaki-zdiisnyly-ponad-5-tys-kiberatak-na-derzhavni-orhany-ukrainy",
            "date": "2021-11-04"
          }
        ]
      }
    ],
    "flag": "🇷🇺",
    "profile": "/apt/gamaredon/"
  }
}