G0047: Gamaredon Group
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.CitationPalo Alto Gamaredon Feb 2017CitationTrendMicro Gamaredon April 2020CitationESET Gamaredon June 2020CitationSymantec Shuckworm January 2022CitationMicrosoft Actinium February 2022
In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. CitationBleepingcomputer Gamardeon FSB November 2021CitationMicrosoft Actinium February 2022
Security context for executives and security teams
Gamaredon Group matters as an espionage-focused intrusion set with long-running reporting against Ukrainian military, law enforcement, judiciary, nonprofit, and NGO organizations. For leaders, the value of this ATT&CK object is not a single indicator list; it is a behavioral profile that highlights information theft, persistence of operations over time, use of legitimate utilities, and alias sprawl across vendors. Organizations with Ukraine-related operations, partners, missions, or regulatory evidence needs should use this profile to validate whether SOC and IR teams can recognize collection, command-and-control, and exfiltration behaviors rather than relying only on malware names.
Executive priority
Prioritize this as a resilience and intelligence-driven readiness issue when the organization has Ukraine exposure, government/NGO/legal-sector dependencies, or sensitive information that would be valuable in espionage. Executives should ask whether threat intelligence aliases are normalized, whether incident response can quickly assess data access and exfiltration, and whether logging exists for Windows-heavy behaviors reflected in the relationships, including registry activity, WMI, remote access, file collection, and outbound C2-like traffic. Because MITRE provides no official detection text for this group, assurance should come from validated telemetry and tested analytic coverage, not from the presence of a named threat feed alone.
Technical view
ATT&CK relationships associate Gamaredon Group with utilities and malware including Reg, Ping, Pteranodon, Remcos, PowerPunch, and QuietSieve, and with techniques spanning discovery, collection, stealth, command-and-control, lateral movement, execution, and exfiltration. SOC and detection teams should validate behavior-based coverage for registry querying, internet connectivity checks, WMI execution, VNC use, obfuscated commands/files, LNK icon smuggling, compression, data collection from local systems/removable media/network shares, automated exfiltration, and exfiltration over C2 channels. Treat Reg, Ping, WMI, and VNC as high false-positive areas: useful detections will need baselines, parent/child process context, user and host role context, network destination context, and correlation with suspicious file or data-access activity.
Likely telemetry
- Endpoint process creation with command-line arguments and parent/child process context
- Windows Registry access and command-line use of Reg where available
- WMI execution and remote management logs on Windows systems
- Network connection, proxy, firewall, DNS, and egress metadata for C2-like or obfuscated traffic patterns
- Authentication and remote access telemetry for VNC or similar remote-control activity
Detection direction
- Normalize threat intelligence aliases including Gamaredon Group, IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, and NastyShrew so investigations are not fragmented by vendor naming.
- Build detections around behavior chains rather than single tools: discovery activity followed by file collection, obfuscation, outbound C2, or exfiltration is higher value than isolated Ping or Reg execution.
- Tune legitimate-administration noise for Reg, Ping, WMI, and VNC by host role, administrator identity, maintenance windows, and expected destinations.
- Validate coverage for collection paths called out by related techniques: local systems, removable media, and network shared drives.
- Test whether SOC workflows can pivot from suspected C2 or exfiltration to user, host, file-access, and data-sensitivity context quickly enough for incident response decisions.
Mitigation priorities
- Start with exposure scoping: identify business units, partners, missions, or data sets where Ukraine-related espionage risk is relevant.
- Ensure endpoint, identity, network, and file-access logs are retained and searchable for the related behaviors before relying on detections.
- Harden and monitor administrative paths reflected in the relationships, including WMI, registry tooling, and remote access such as VNC.
- Limit unnecessary access to sensitive network shares and removable media use, and validate that access is auditable.
- Apply egress controls and monitoring that can support investigation of automated exfiltration and exfiltration over C2 channels.
Additional notes and limits
The supplied ATT&CK object is a group profile, not a procedure-level detection specification. Its strongest decision value comes from the relationship context: Windows-associated tooling, custom and commodity remote-access or downloader/stealer software, and techniques covering discovery, stealth, collection, C2, and exfiltration. The official description supports suspected Russian cyber espionage activity against Ukrainian sectors since at least 2013 and notes public Ukrainian attribution to Russia’s FSB Center 18, later supported by independent researchers.
MITRE provides no official detection guidance, no platforms on the group object itself, and no tactics directly on the group object. Platform and tactic observations in this take are derived only from the supplied related software and technique records. Local telemetry, business exposure, and environment baselines are required before judging risk, coverage, or likely activity in any specific organization.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Gamaredon Group
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.CitationPalo Alto Gamaredon Feb 2017CitationTrendMicro Gamaredon April 2020CitationESET Gamaredon June 2020CitationSymantec Shuckworm January 2022CitationMicrosoft Actinium February 2022
In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. CitationBleepingcomputer Gamardeon FSB November 2021CitationMicrosoft Actinium February 2022
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
