Gamaredon Group
Also tracked as IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.
- Known attack methods
- 70
- Origin
- Russia
- Motive
- Espionage
- First seen
- 2013
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques
Resource Development
9 techniques · 4 used
Initial Access
11 techniques · 1 used
Execution
20 techniques · 6 used
Persistence
22 techniques · 2 used
Privilege Escalation
13 techniques
Stealth
30 techniques · 11 used
Defense Impairment
18 techniques · 2 used
Credential Access
17 techniques
Discovery
34 techniques · 8 used
Lateral Movement
9 techniques · 4 used
Collection
17 techniques · 5 used
Command and Control
18 techniques · 8 used
Exfiltration
9 techniques · 2 used
Impact
15 techniques · 2 used
Resource development6
Initial access1
Execution9
Stealth17
- T1027Obfuscated Files or Information
- T1027.004Compile After Delivery
- T1027.010Command Obfuscation
- T1027.012LNK Icon Smuggling
- T1027.015Compression
- T1027.016Junk Code Insertion
- T1036.005Match Legitimate Resource Name or Location
- T1055Process Injection
- T1070.004File Deletion
- T1140Deobfuscate/Decode Files or Information
- T1218.005Mshta
- T1218.011Rundll32
- T1221Template Injection
- T1480Execution Guardrails
- T1497.001System Checks
- T1564.003Hidden Window
- T1620Reflective Code Loading
Defense impairment2
Discovery8
Lateral movement4
Collection5
Command and control12
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.