All actors

Gamaredon Group

Also reported as IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm and 3 other names.

Reports
200
Last reported
Known CVEs
147
Techniques in ATT&CK
70
ID
G0047
Sources
ATT&CK
Merge evidence
0 alias matches

Reports per quarter

  1. 2016 Q2: 1 report
  2. 2016 Q3: no reports
  3. 2016 Q4: no reports
  4. 2017 Q1: 5 reports
  5. 2017 Q2: no reports
  6. 2017 Q3: no reports
  7. 2017 Q4: no reports
  8. 2018 Q1: 1 report
  9. 2018 Q2: no reports
  10. 2018 Q3: 1 report
  11. 2018 Q4: no reports
  12. 2019 Q1: 4 reports
  13. 2019 Q2: no reports
  14. 2019 Q3: 6 reports
  15. 2019 Q4: 3 reports
  16. 2020 Q1: 9 reports
  17. 2020 Q2: 12 reports
  18. 2020 Q3: 4 reports
  19. 2020 Q4: 4 reports
  20. 2021 Q1: 7 reports
  21. 2021 Q2: 7 reports
  22. 2021 Q3: 1 report
  23. 2021 Q4: 7 reports
  24. 2022 Q1: 23 reports
  25. 2022 Q2: 18 reports
  26. 2022 Q3: 11 reports
  27. 2022 Q4: 10 reports
  28. 2023 Q1: 9 reports
  29. 2023 Q2: 2 reports
  30. 2023 Q3: 3 reports
  31. 2023 Q4: 2 reports
  32. 2024 Q1: 4 reports
  33. 2024 Q2: 3 reports
  34. 2024 Q3: 2 reports
  35. 2024 Q4: 4 reports
  36. 2025 Q1: 3 reports
  37. 2025 Q2: 4 reports
  38. 2025 Q3: 3 reports
  39. 2025 Q4: 3 reports
  40. 2026 Q1: no reports
  41. 2026 Q2: 24 reports
Dated reports, 2016 Q2 to 2026 Q2.

Techniques seen in the last two years

Show all 49 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 46 techniques Show fewer

CVEs named in reports

Show all 147 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

Show all 200 reports Show fewer
  1. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

  2. Remcos (Malware Family)

    date ORKL added it fromORKL

  3. How Microsoft names threat actors

    date in the title fromORKL

  4. Microsoft Security Compliance and Identity

    Malpedia library date Microsoft fromORKL

  5. Following the LNK metadata trail

    date in the title fromORKL

  6. Reassessing cyberwarfare. Lessons learned in 2022

    date in the title fromORKL

  7. Gamaredon APT targets Ukrainian government agencies in new campaign

    date in the CCS '25 data CiscoTalos fromORKLCCS '25 data

  8. Shuckworm- Russia-Linked Group Maintains Ukraine Focus

    date in the title fromORKL

  9. Disrupting SEABORGIUM’s ongoing phishing operations

    date in the title fromORKL

  10. Growling Bears Make Thunderous Noise

    date in the title fromORKL

  11. eset_threat_report_t12022

    file creation date fromORKL

  12. Gamaredon Group Understanding the Russian APT

    date in the title fromORKL

  13. Gamaredon Group- Understanding the Russian APT

    date in the title fromORKL

  14. Network Footprints of Gamaredon Group

    date in the title fromORKL

  15. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  16. Russian State-Sponsored and Criminal Cyber .pdf

    file creation date fromORKL

  17. Ukraine CyberWar Overview

    date in the title fromORKL

  18. Cyberattacks are Prominent in the Russia-Ukraine Conflict

    date in the title fromORKL

  19. Cyber threat activity in Ukraine- analysis and resources

    date in the title fromORKL

  20. HermeticWiper & resurgence of targeted attacks on Ukraine

    date in the title fromORKL

  21. ACTINIUM targets Ukrainian organizations

    date in the title fromORKL

  22. ACTINIUM targets Ukrainian organizations

    date in the CCS '25 data microsoft fromORKLCCS '25 data

  23. Gamaredon (Primitive Bear) Russian APT Group Actively Targeting Ukraine

    date in the CCS '25 data palo alto networks fromORKLCCS '25 data

  24. Shuckworm_APT

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  25. Technical report Armagedon

    Malpedia library date CrowdStrike fromORKLCCS '25 data

  26. APT trends report Q3 2021

    date in the title fromORKL

  27. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  28. eset_threat_report_t22021

    file creation date fromORKL

  29. Elizabethan England has nothing on modern-day Russia

    date in the title fromORKL

  30. APT_trends_report_Q1_2021_Securelist

    file creation date fromORKL

  31. APT trends report Q1 2021

    date in the title fromORKL

  32. CERT-UA

    Malpedia library date fromORKL

  33. Gamaredon - When nation states don’t pay all the bills

    date in the title fromORKL

  34. Docx Files Template-Injection

    date in the title fromORKL

  35. Cybersecurity_threatscape-2020-Q3.ENG

    file creation date fromORKL

  36. Russian cyber attack campaigns and actors

    date in the title fromORKL

  37. ESET_Threat_Report_Q32020

    file creation date fromORKL

  38. cybersecurity-threatscape-2020-q2-eng

    file creation date fromORKL

  39. ESET_Threat_Report_Q22020

    file creation date fromORKL

  40. cybersecurity-threatscape-2020-q1-eng

    file creation date fromORKL

  41. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  42. Digging up InvisiMole’s hidden arsenal

    date in the title fromORKL

  43. Gamaredon group grows its game _ WeLiveSecurity

    date in the CCS '25 data ESET fromORKLCCS '25 data

  44. Gamaredon group grows its game

    date in the title fromORKL

  45. ESET_InvisiMole

    Malpedia library date fromORKL

  46. 200407-MWB-COVID-White-Paper_Final

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  47. cybersecurity-threatscape-2019-q4-eng

    file creation date fromORKL

  48. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  49. Cyberwarfare_ A deep dive into the latest Gamaredon Espionage Campaign

    date in the CCS '25 data Yoroi fromORKLCCS '25 data

  50. Playing defense against Gamaredon Group

    date in the title fromORKL

  51. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  52. Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs

    Malpedia library date Recorded Future fromORKLCCS '25 data

  53. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  54. cybersecurity-threatscape-2019-q3-eng

    file creation date fromORKL

  55. Gamaredon Analysis

    date in the title fromORKL

  56. The Gamaredon Group_ A TTP Profile Analysis

    file creation date fromORKL

  57. EvilGnome- Rare Malware Spying on Linux Desktop Users

    date in the title fromORKL

  58. EvilGnome_ Rare Malware Spying on Desktop Users

    date in the CCS '25 data Intezer fromORKLCCS '25 data

  59. GREIN-Grupo-GAMAREDON.pdf

    file creation date fromORKL

  60. Eset-Turla-Outlook-Backdoor

    Malpedia library date ESET fromORKLCCS '25 data

  61. CERT-UA

    Malpedia library date fromORKL

  62. The Gamaredon Group Toolset Evolution

    file creation date Palo Alto Networks fromORKL

  63. The Gamaredon Group Toolset Evolution

    Malpedia library date fromORKL

  64. The Gamaredon Group Toolset Evolution - Palo Alto Networks Blog

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  65. The Gamaredon Group Toolset Evolution

    date in the title fromORKL

Newest first. Details opens the report in Explore.