Gamaredon Group
Also reported as IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm and 3 other names.
Reports per quarter
Techniques seen in the last two years
- T1566.001 5 reports in ATT&CK
- T1566.002 4 reports reports only
- T1091 3 reports in ATT&CK
- T1190 3 reports reports only
- T1659 3 reports reports only
- T1027.006 2 reports reports only
- T1059.001 2 reports in ATT&CK
- T1059.007 2 reports reports only
- T1071.001 2 reports in ATT&CK
- T1189 2 reports reports only
Show all 49 techniques Show fewer
- T1195 2 reports reports only
- T1204.002 2 reports in ATT&CK
- T1566.003 2 reports reports only
- T1583.001 2 reports in ATT&CK
- T1583.004 2 reports reports only
- T1012 1 report in ATT&CK
- T1027.002 1 report reports only
- T1027.010 1 report in ATT&CK
- T1027.012 1 report in ATT&CK
- T1027.013 1 report reports only
- T1036 1 report reports only
- T1036.005 1 report in ATT&CK
- T1041 1 report in ATT&CK
- T1055.002 1 report reports only
- T1057 1 report in ATT&CK
- T1059.005 1 report in ATT&CK
- T1082 1 report in ATT&CK
- T1083 1 report in ATT&CK
- T1102 1 report in ATT&CK
- T1105 1 report in ATT&CK
- T1140 1 report in ATT&CK
- T1204.001 1 report in ATT&CK
- T1204.004 1 report reports only
- T1212 1 report reports only
- T1480.001 1 report reports only
- T1547.001 1 report in ATT&CK
- T1557 1 report reports only
- T1568.001 1 report in ATT&CK
- T1571 1 report in ATT&CK
- T1573.001 1 report reports only
- T1583.003 1 report in ATT&CK
- T1583.007 1 report reports only
- T1584.001 1 report reports only
- T1584.003 1 report reports only
- T1591 1 report reports only
- T1591.002 1 report reports only
- T1608 1 report reports only
- T1608.001 1 report in ATT&CK
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-5633
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4404 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0096
- CVE-2015-0554
Show all 147 CVEs Show fewer
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-2051 KEV
- CVE-2015-2545 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-8570 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-13382 KEV ransomware
- CVE-2018-13383 KEV ransomware
- CVE-2018-1579
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-5407
- CVE-2018-6055
- CVE-2018-8453 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11043 KEV ransomware
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1182
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-15126
- CVE-2019-1653 KEV
- CVE-2019-16759 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-5840
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0968 KEV ransomware
- CVE-2020-10173
- CVE-2020-11651 KEV
- CVE-2020-11652 KEV
- CVE-2020-14882 KEV
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-2021 KEV ransomware
- CVE-2020-3259 KEV ransomware
- CVE-2020-35730 KEV
- CVE-2020-3702
- CVE-2020-4006 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1636
- CVE-2021-1732 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-21974
- CVE-2021-26334
- CVE-2021-26411 KEV ransomware
- CVE-2021-2641111
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30665 KEV
- CVE-2021-30666 KEV
- CVE-2021-32648 KEV
- CVE-2021-3438
- CVE-2021-34448 KEV
- CVE-2021-344486
- CVE-2021-34523 KEV ransomware
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-0847 KEV
- CVE-2022-2294 KEV ransomware
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26766
- CVE-2022-27924 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-41352 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-11182 KEV
- CVE-2024-21413 KEV
- CVE-2024-42009 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
- CVE-2024-9680 KEV ransomware
- CVE-2025-0411 KEV
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2026-22813
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Gamaredon Group - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Gamaredon Group - Threat Group Cards: A Threat Actor Encyclopedia
-
Gamaredon APT Group Use Covid-19 Lure in Campaigns
The original link failed its last check. Original publisher Detailsfor Gamaredon APT Group Use Covid-19 Lure in Campaigns
Show all 200 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Remcos (Malware Family)
-
How Microsoft names threat actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Microsoft names threat actors
-
Microsoft Security Compliance and Identity
The original link failed its last check. Original publisher Detailsfor Microsoft Security Compliance and Identity
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Three Cases of Cyber Attacks on the Security Service of Ukraine and NATO Allies, Likely by Russian State-Sponsored Gamaredon
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberattacks Targeting Ukraine Increase 20-fold at End of 2022 Fueled by Russia-linked Gamaredon Activity
-
Following the LNK metadata trail
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Following the LNK metadata trail
-
Gamaredon (Ab)uses Telegram to Target Ukrainian Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon (Ab)uses Telegram to Target Ukrainian Organizations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine
-
Russian hackers targeted petroleum refining company in NATO state
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers targeted petroleum refining company in NATO state
-
Reassessing cyberwarfare. Lessons learned in 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reassessing cyberwarfare. Lessons learned in 2022
-
Calisto show interests into entities involved in Ukraine war support
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Calisto show interests into entities involved in Ukraine war support
-
Gamaredon Leverages Microsoft Office Docs to Target Ukraine Government and Military
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon Leverages Microsoft Office Docs to Target Ukraine Government and Military
-
Gamaredon APT targets Ukrainian government agencies in new campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon APT targets Ukrainian government agencies in new campaign
-
Gamaredon APT targets Ukrainian government agencies in new campaign
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Gamaredon APT targets Ukrainian government agencies in new campaign
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
-
Shuckworm- Russia-Linked Group Maintains Ukraine Focus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shuckworm- Russia-Linked Group Maintains Ukraine Focus
-
Disrupting SEABORGIUM’s ongoing phishing operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Disrupting SEABORGIUM’s ongoing phishing operations
-
Early Analysis of the Twilio phishing attack-it is the tip of the iceberg
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Early Analysis of the Twilio phishing attack-it is the tip of the iceberg
-
Growling Bears Make Thunderous Noise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Growling Bears Make Thunderous Noise
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
Gamaredon Group Understanding the Russian APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon Group Understanding the Russian APT
-
Gamaredon Group- Understanding the Russian APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon Group- Understanding the Russian APT
-
Network Footprints of Gamaredon Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Network Footprints of Gamaredon Group
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
Shuckworm- Espionage Group Continues Intense Campaign Against Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shuckworm- Espionage Group Continues Intense Campaign Against Ukraine
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Shuckworm: Espionage Group Continues Intense Campaign Against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Shuckworm: Espionage Group Continues Intense Campaign Against Ukraine
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine CyberWar Overview
-
A Closer Look at the Russian Actors Targeting Organizations in Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Closer Look at the Russian Actors Targeting Organizations in Ukraine
-
Cyberattacks are Prominent in the Russia-Ukraine Conflict
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberattacks are Prominent in the Russia-Ukraine Conflict
-
Cyber threat activity in Ukraine- analysis and resources
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber threat activity in Ukraine- analysis and resources
-
HermeticWiper & resurgence of targeted attacks on Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HermeticWiper & resurgence of targeted attacks on Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia-Ukraine Cyberattacks Updated How to Protect Against Related Cyberthreats Including DDoS Hermet
-
Shuckworm Continues Cyber-Espionage Attacks Against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Shuckworm Continues Cyber-Espionage Attacks Against Ukraine
-
ACTINIUM targets Ukrainian organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ACTINIUM targets Ukrainian organizations
-
ACTINIUM targets Ukrainian organizations
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor ACTINIUM targets Ukrainian organizations
-
Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine (Updated June 22)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine (Updated June 22)
-
Gamaredon (Primitive Bear) Russian APT Group Actively Targeting Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Gamaredon (Primitive Bear) Russian APT Group Actively Targeting Ukraine
-
Russias Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russias Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Shuckworm_APT
-
Russian 'Gamaredon' hackers use 8 new malware payloads in attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian 'Gamaredon' hackers use 8 new malware payloads in attacks
-
Shuckworm Continues Cyber-Espionage Attacks Against Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shuckworm Continues Cyber-Espionage Attacks Against Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Injection is the New Black- Novel RTF Template Inject Technique Poised for Widespread Adoption Beyond APT Actors
-
Is a coordinated cyberattack brewing in the escalating Russian-Ukrainian conflict-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Is a coordinated cyberattack brewing in the escalating Russian-Ukrainian conflict-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Technical report Armagedon
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
Elizabethan England has nothing on modern-day Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elizabethan England has nothing on modern-day Russia
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
PRIMITIVE BEAR (Gamaredon) Targets Ukraine with Timely Themes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PRIMITIVE BEAR (Gamaredon) Targets Ukraine with Timely Themes
-
Gamaredon - When nation states don’t pay all the bills
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon - When nation states don’t pay all the bills
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Docx Files Template-Injection
-
Cybersecurity_threatscape-2020-Q3.ENG
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cybersecurity_threatscape-2020-Q3.ENG
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT model worker- A summary of the activities of the Eastern European hacker group using spear phishing emails to attack Ukraine
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
cybersecurity-threatscape-2020-q2-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2020-q2-eng
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
cybersecurity-threatscape-2020-q1-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2020-q1-eng
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
A close look at the advanced techniques used in a Malaysian-focused APT campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A close look at the advanced techniques used in a Malaysian-focused APT campaign
-
Digging up InvisiMole’s hidden arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digging up InvisiMole’s hidden arsenal
-
Gamaredon group grows its game _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon group grows its game _ WeLiveSecurity
-
Gamaredon group grows its game
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon group grows its game
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_InvisiMole
-
Gamaredon APT Group Use Covid-19 Lure in Campaigns - TrendLabs Security Intelligence Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon APT Group Use Covid-19 Lure in Campaigns - TrendLabs Security Intelligence Blog
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Cyberwarfare- A deep dive into the latest Gamaredon Espionage Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberwarfare- A deep dive into the latest Gamaredon Espionage Campaign
-
Cyberwarfare_ A deep dive into the latest Gamaredon Espionage Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberwarfare_ A deep dive into the latest Gamaredon Espionage Campaign
-
Playing defense against Gamaredon Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Playing defense against Gamaredon Group
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Pro-Russian CyberSpy Gamaredon Intensifies Ukrainian Security Targeting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pro-Russian CyberSpy Gamaredon Intensifies Ukrainian Security Targeting
-
Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
cybersecurity-threatscape-2019-q3-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q3-eng
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon Analysis
-
The Gamaredon Group_ A TTP Profile Analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Gamaredon Group_ A TTP Profile Analysis
-
2019 Cyber Threatscape Report I Accenture
The original link failed its last check. Original publisher Detailsfor 2019 Cyber Threatscape Report I Accenture
-
EvilGnome- Rare Malware Spying on Linux Desktop Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor EvilGnome- Rare Malware Spying on Linux Desktop Users
-
EvilGnome_ Rare Malware Spying on Desktop Users
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor EvilGnome_ Rare Malware Spying on Desktop Users
-
An Inside Look at the Infrastructure Behind the Russian APT Gamaredon Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Inside Look at the Infrastructure Behind the Russian APT Gamaredon Group
-
The original link failed its last check. Original publisher Detailsfor GREIN-Grupo-GAMAREDON.pdf
-
Let's Learn- Deeper Dive into Gamaredon Group Pteranodon Implant Version '_512'
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Let's Learn- Deeper Dive into Gamaredon Group Pteranodon Implant Version '_512'
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Eset-Turla-Outlook-Backdoor
-
The Gamaredon Group Toolset Evolution
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Gamaredon Group Toolset Evolution
-
The Gamaredon Group Toolset Evolution
The original link failed its last check. Original publisher Detailsfor The Gamaredon Group Toolset Evolution
-
The Gamaredon Group Toolset Evolution - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Gamaredon Group Toolset Evolution - Palo Alto Networks Blog
-
The Gamaredon Group Toolset Evolution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Gamaredon Group Toolset Evolution
Newest first. Details opens the report in Explore.