Initial Access
1 technique·derived
Very high volume, Ukrainian-language government-themed lures.
FSB officers operating from occupied Crimea, publicly named by Ukraine's security service. Enormous volume, minimal sophistication, relentlessly focused on Ukraine.
ATTRIBUTED TORussia › FSB — Federal Security Service › 18th Centre / Crimean directorate
Gamaredon is the loudest state actor in operation, and deliberately so. It runs enormous volumes of phishing against Ukrainian government, military, and law enforcement targets with tooling that is by any technical measure unsophisticated — VBScript droppers, self-modifying batch files, and rapid domain churn through free dynamic-DNS providers.
That crudeness is a strategy, not a shortcoming. The group operates on the assumption that most of its infrastructure will be burned within days, so it rotates C2 domains constantly and re-infects the same organisations repeatedly. Defenders describe fighting Gamaredon as an endless cleanup rather than a discrete incident.
In November 2021 Ukraine's Security Service (SSU) published an unusually detailed exposure: it named five FSB officers by name, identified them as serving in the FSB's Crimean directorate, and released intercepted communications. Several of the named individuals were Ukrainian SBU officers who defected to Russian service following the 2014 annexation of Crimea.
Its practical significance is as a scouting layer. CERT-UA and ESET have both documented more capable Russian services — including Turla — deploying implants onto hosts that Gamaredon compromised first, effectively treating the group's mass access as a target-selection pipeline.
Down to the named unit where public evidence supports it.
FSB Office in the Republic of Crimea and Sevastopol
Ukraine's Security Service publicly identified five FSB officers by name in November 2021, attributing Gamaredon to the FSB's directorate in occupied Crimea and releasing intercepted communications as supporting evidence. Several named individuals were former SBU officers who defected after the 2014 annexation. CERT-UA tracks the activity as UAC-0010, and the attribution is corroborated by ESET and Unit 42 reporting.
Attributing sources
11 designators across 10 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Descriptive names, frequently derived from the group's flagship malware family.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
The group's flagship implant family, continuously rewritten in VBScript, C#, and compiled variants to defeat signatures.
Malpedia ↗VBScript downloader retrieving further stages from rapidly rotating dynamic-DNS domains.
PowerShell exfiltration script harvesting documents by extension from local and removable drives.
USB-propagating worm that spreads to removable media, producing incidental infections well beyond the intended target set.
PowerShell downloader that keys its payload decryption to the target host, frustrating sandbox analysis.
Shared, commodity & living-off-the-land
Office documents that fetch a weaponised template only when opened by the intended victim.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by Gamaredon | ||
|---|---|---|---|---|
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jun 2018 | Equation Editor overflow in phishing documents against Ukrainian government targets.SRCUnit 42 ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Mar 2018 | OLE2link RTF exploit in Ukrainian-language lure documents delivering Pterodo.SRCESET ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Very high volume, Ukrainian-language government-themed lures.
2 techniques·derived
Visual Basic, PowerShell.
2 techniques·derived
Registry Run Keys, Scheduled Task.
1 technique·derived
Remote template fetch on document open.
1 technique·derived
LitterDrifter USB worm.
2 techniques·derived
Data from Local System, Screen Capture.
2 techniques·derived
Heavy use of free dynamic-DNS providers with sub-daily rotation. Telegram channels used as dead drops for C2 addresses.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Very high volume, Ukrainian-language government-themed lures
Remote template fetch on document open
LitterDrifter USB worm
Heavy use of free dynamic-DNS providers with sub-daily rotation
Telegram channels used as dead drops for C2 addresses
Continuous high-volume phishing against Ukrainian government, military, and law enforcement since the annexation of Crimea, with more than 5,000 attacks attributed by Ukraine's Security Service. Deliberately noisy and constantly rebuilt, functioning in practice as a scouting layer for more capable Russian services.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
ESET documented Turla deploying its own implants onto hosts Gamaredon had already compromised — the noisy group functioning as a target-selection layer for the sophisticated one.
Frequently present in the same Ukrainian victim networks; different services with distinct objectives.
Both Russian state services targeting Ukraine; FSB and GRU respectively.
Curated links to the reports that established what is known about this group.