Gamaredon Group
MISPUnknown
RU
Unknown
[Gamaredon Group](https://attack.mitre.org/groups/G0047) is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name [Gamaredon Group](https://attack.mitre.org/groups/G0047) derives from a misspelling of the word "Armageddon," found in early campaigns.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: TrendMicro Gamaredon April 2020)(Citation: ESET Gamaredon June 2020)(Citation: Symantec Shuckworm January 2022)(Citation: Microsoft Actinium February 2022)
In November 2021, the Ukrainian government publicly attributed [Gamaredon Group](https://attack.mitre.org/groups/G0047) to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. (Citation: Bleepingcomputer Gamardeon FSB November 2021)(Citation: Microsoft Actinium February 2022)
Techniques Used (70)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1001 | Data Obfuscation | - |
| T1005 | Data from Local System | - |
| T1012 | Query Registry | - |
| T1016.001 | Internet Connection Discovery | - |
| T1020 | Automated Exfiltration | - |
| T1021.005 | VNC | - |
| T1025 | Data from Removable Media | - |
| T1027 | Obfuscated Files or Information | - |
| T1027.004 | Compile After Delivery | - |
| T1027.010 | Command Obfuscation | - |
| T1027.012 | LNK Icon Smuggling | - |
| T1027.015 | Compression | - |
| T1027.016 | Junk Code Insertion | - |
| T1033 | System Owner/User Discovery | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
References (10)
- researchcenter.paloaltonetworks.com - Unit 42 Title Gamaredon Group Toolset Evolution
- lookingglasscyber.com - Operation Armageddon Final.pdf
- unit42.paloaltonetworks.com - Unit 42 Title Gamaredon Group Toolset Evolution
- attack.mitre.org - G0047
- github.com - Gamaredon
- go.crowdstrike.com - Report2020CrowdStrikeGlobalThreatReport.pdf
- welivesecurity.com - Digging Up Invisimole Hidden Arsenal
- symantec-enterprise-blogs.security.com - Shuckworm Gamaredon Espionage Ukraine
- microsoft.com - Actinium Targets Ukrainian Organizations
- welivesecurity.com - Gamaredon Group Grows Its Game
Aliases (2120)
Related Malware (6)
Metadata
| ID: | 103 |
| Created: | 13/01/2026 17:48 |
| Updated: | 07/03/2026 16:00 |