Skip to content
RussiaState-SponsoredActiveMITRE G0047Malpedia ↗

Gamaredon

FSB officers operating from occupied Crimea, publicly named by Ukraine's security service. Enormous volume, minimal sophistication, relentlessly focused on Ukraine.

ATTRIBUTED TORussia › FSB — Federal Security Service › 18th Centre / Crimean directorate

Open MITRE Navigator layer ↗Download profile JSON
Active
2013–present
Motivation
Espionage
Aliases
11
Exploited CVEs
2
ATT&CK techniques
11
Cited sources
8

Overview

Gamaredon is the loudest state actor in operation, and deliberately so. It runs enormous volumes of phishing against Ukrainian government, military, and law enforcement targets with tooling that is by any technical measure unsophisticated — VBScript droppers, self-modifying batch files, and rapid domain churn through free dynamic-DNS providers.

That crudeness is a strategy, not a shortcoming. The group operates on the assumption that most of its infrastructure will be burned within days, so it rotates C2 domains constantly and re-infects the same organisations repeatedly. Defenders describe fighting Gamaredon as an endless cleanup rather than a discrete incident.

In November 2021 Ukraine's Security Service (SSU) published an unusually detailed exposure: it named five FSB officers by name, identified them as serving in the FSB's Crimean directorate, and released intercepted communications. Several of the named individuals were Ukrainian SBU officers who defected to Russian service following the 2014 annexation of Crimea.

Its practical significance is as a scouting layer. CERT-UA and ESET have both documented more capable Russian services — including Turla — deploying implants onto hosts that Gamaredon compromised first, effectively treating the group's mass access as a target-selection pipeline.

Attribution

Down to the named unit where public evidence supports it.

RussiaFSB — Federal Security Service18th Centre / Crimean directorateConfirmed

FSB Office in the Republic of Crimea and Sevastopol

Ukraine's Security Service publicly identified five FSB officers by name in November 2021, attributing Gamaredon to the FSB's directorate in occupied Crimea and releasing intercepted communications as supporting evidence. Several named individuals were former SBU officers who defected after the 2014 annexation. CERT-UA tracks the activity as UAC-0010, and the attribution is corroborated by ESET and Unit 42 reporting.

Attributing sources

Cross-vendor naming crosswalk

11 designators across 10 organisations.

MITRE ATT&CK

index ↗
  • Gamaredon Group

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Aqua BlizzardFormerly ACTINIUM
  • ACTINIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Primitive Bear

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • UNC530

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • IRON TILDEN

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Trident Ursa

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • BlueAlpha

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

ESET Research

index ↗
  • Gamaredon

Descriptive names, frequently derived from the group's flagship malware family.

Symantec (Broadcom)

index ↗
  • Shuckworm

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • ArmageddonAlso the group's self-styled name, from which 'Gamaredon' is an anagrammatic derivation

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

UkraineLatviaLithuaniaPolandBulgariaGeorgia

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Pterodo / Pteranodonbackdoor

The group's flagship implant family, continuously rewritten in VBScript, C#, and compiled variants to defeat signatures.

Malpedia ↗
GammaLoadloader

VBScript downloader retrieving further stages from rapidly rotating dynamic-DNS domains.

GammaSteelutility

PowerShell exfiltration script harvesting documents by extension from local and removable drives.

LitterDriftermalware

USB-propagating worm that spreads to removable media, producing incidental infections well beyond the intended target set.

PowerPunchloader

PowerShell downloader that keys its payload decryption to the target host, frustrating sandbox analysis.

Shared, commodity & living-off-the-land

Remote template injectionutility

Office documents that fetch a weaponised template only when opened by the intended victim.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Gamaredon
CVE-2017-11882KEVransomware7.81 Jun 2018Equation Editor overflow in phishing documents against Ukrainian government targets.SRCUnit 42
CVE-2017-0199KEVransomware7.81 Mar 2018OLE2link RTF exploit in Ukrainian-language lure documents delivering Pterodo.SRCESET

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 11 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
11 techniques across 7 tactics · 5 with actor-specific notes

Initial Access

1

Defense Evasion

1

Lateral Movement

1

Command and Control

2

Campaign timeline

  1. Sustained Ukrainian Government Targeting

    Continuous high-volume phishing against Ukrainian government, military, and law enforcement since the annexation of Crimea, with more than 5,000 attacks attributed by Ukraine's Security Service. Deliberately noisy and constantly rebuilt, functioning in practice as a scouting layer for more capable Russian services.

    CVE-2017-0199CVE-2017-11882GovernmentDefenseCritical InfrastructureMedia & Journalism

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.