Skip to main content
Mallory
Russia🇷🇺 RU41 malware familiesExploits CVEs in the wild

Gamaredon Group

Also known asACTINIUMAPT-C-53Aqua BlizzardArmageddonDEV-0157gamaredongamaredon_groupIRON TILDENPRIMITIVE BEARSectorC08Shuckwormtrident_ursaUNC530

Gamaredon is a Russia-linked, state-sponsored cyberespionage threat actor officially linked in the provided reporting to Russia’s Federal Security Service (FSB). The group has been active since at least 2013/2014 and is consistently described as focusing primarily on Ukraine. Reported targets include Ukrainian government, military, critical infrastructure, law enforcement, journalists, NGOs, and other national security-related organizations. Known aliases in the provided content include Actinium, APT-C-53, Aqua Blizzard, Armageddon, DEV-0157, Gamaredon, Iron Tilden, Primitive Bear, SectorC08, Shuckworm, Trident Ursa, UNC530, UAC-0010, BlueAlpha, and ACTINUM. The content also notes that SBU publicly associated Callisto/Calisto with Gamaredon, but that this link is not supported by other security companies or researchers. The group is described as specializing in long-term, persistent intrusion and espionage operations against Ukraine, with heavy use of spear-phishing and malicious attachments, including booby-trapped RAR archives. Recent reporting in the provided content describes exploitation of the WinRAR path traversal vulnerability CVE-2025-8088 to deliver a modular malware chain. Sekoia grouped this tooling under a "Gamma" taxonomy including GammaPhish, GammaLoad, GammaWorm, GammaSteel, and GammaWipe/GamaWiper. In that chain, weaponized XHTML lures and HTML smuggling delivered malicious RAR archives that placed an HTA file in the Windows Startup folder, leading to execution via mshta.exe. GammaLoad was described as a VBScript staging component used to fingerprint hosts, update registry-based network configuration through dead-drop resolvers, and fetch arbitrary VBScript payloads from command-and-control servers. GammaWorm was described as a heavily obfuscated VBScript worm that stores modules in NTFS Alternate Data Streams, persists via RunOnce registry keys and scheduled tasks, and propagates through USB drives and network shares by hiding legitimate folders and replacing them with malicious LNK shortcuts. The group’s infrastructure resolution and C2 concealment techniques include use of Telegram channels, Telegra.ph, graph.org, Teletype, Cloudflare Workers, public third-party websites, ngrok, TXT records, and cloud storage. GammaSteel was described as a modular information stealer that collects targeted files and exfiltrates them to AWS S3 or other actor-controlled servers. Additional behaviors directly mentioned in the content include use of obfuscated PowerShell scripts for staging, batch scripts for C2 establishment and payload download, registry Run keys for persistence, process enumeration including Process Explorer, file collection and upload to C2, removable-drive scanning, and deletion of files used during operations. The content also states that ESET presented technical evidence in 2025 that Gamaredon facilitated Turla access to high-value Ukrainian targets. In incidents observed between February and June 2025, Gamaredon tooling including PteroGraphin and PteroOdd was used to deploy Turla’s Kazuar backdoor, and in at least one case Gamaredon restored Turla’s access after Turla appeared to lose its foothold. The reporting characterizes this as direct operational collaboration and a division of labor in which Gamaredon establishes or maintains access while Turla deploys a more advanced espionage platform.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇺🇦 Ukraine

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics57 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1091×4
Replication Through Removable Media
T1566×4
Phishing
T1566.001×4
Spearphishing Attachment
TA0002
Execution
5 techniques
T1053
Scheduled Task/Job
T1053.005×5
Scheduled Task
T1059×3
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.005×6
Visual Basic
T1127
Trusted Developer Utilities Proxy Execution
T1203×5
Exploitation for Client Execution
T1204
User Execution
T1204.002×3
Malicious File
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005×5
Scheduled Task
T1112×3
Modify Registry
T1547
Boot or Logon Autostart Execution
T1547.001×4
Registry Run Keys / Startup Folder
T1547.009×3
Shortcut Modification
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005×5
Scheduled Task
T1547
Boot or Logon Autostart Execution
T1547.001×4
Registry Run Keys / Startup Folder
T1547.009×3
Shortcut Modification
TA0005
Stealth
5 techniques
T1006
Direct Volume Access
T1027
Obfuscated Files or Information
T1027.006×2
HTML Smuggling
T1127
Trusted Developer Utilities Proxy Execution
T1218
System Binary Proxy Execution
T1218.005×3
Mshta
T1564
Hide Artifacts
T1564.001
Hidden Files and Directories
T1564.004×5
NTFS File Attributes
TA0112
Defense Impairment
1 technique
T1112×3
Modify Registry
TA0007
Discovery
3 techniques
T1057
Process Discovery
T1082×3
System Information Discovery
T1083
File and Directory Discovery
TA0008
Lateral Movement
2 techniques
T1091×4
Replication Through Removable Media
T1570×3
Lateral Tool Transfer
TA0009
Collection
5 techniques
T1005×2
Data from Local System
T1025×2
Data from Removable Media
T1039
Data from Network Shared Drive
T1119
Automated Collection
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
5 techniques
T1071
Application Layer Protocol
T1071.001×2
Web Protocols
T1090
Proxy
T1090.003
Multi-hop Proxy
T1102×2
Web Service
T1102.001×3
Dead Drop Resolver
T1105×6
Ingress Tool Transfer
T1568×2
Dynamic Resolution
TA0010
Exfiltration
3 techniques
T1041×3
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567
Exfiltration Over Web Service
T1567.002×3
Exfiltration to Cloud Storage
ARSENAL

Associated malware families

41 malware families attributed to this actor across reporting.

FamilyContextEvidenceLast seen
PteranodonThe group was tied to the FSB by Ukraine’s Security Service, it originally used off-the-shelf tools like Remote Manipulator System RAT, then moved to a custom framework called Pteranodon, and gradually fragmented into a constellation of standalone, modular malware families.8Jun 4, 2026
GammaLoadThat URL fetches GammaLoad, the intermediate staging layer... “GammaLoad (Staging): We recovered multiple VBScript loaders from the compromised hosts. It seems that these loaders operate in a continuous cascade, with four distinct execution stages observed during our analysis.”7Jun 4, 2026
GammaPhishSekoia has now aligned the naming under a single taxonomy using the “Gamma” prefix: GammaPhish for initial access... “GammaPhish (Initial access): Through YARA-based hunting, we identified a cluster of weaponized xHTML files distributing a malicious RAR archive. This archive exploits the CVE-2025-8088 vulnerability to extract a hidden HTA file directly into the user’s Windows Startup directory.”6Jun 4, 2026
GammaSteelThis is part one of a three-part series; parts two and three cover GammaLoad and GammaSteel, respectively... Sekoia has now aligned the naming under a single taxonomy using the “Gamma” prefix: ... GammaSteel for data theft6Jun 4, 2026
GammaWormGammaWorm is the propagation component... It doesn’t drop traditional files. Instead it writes its core modules into NTFS Alternate Data Streams... The propagation module targets USB drives and network shares.6Jun 4, 2026

36 additional families tracked in Mallory.

WEAPONIZED

Associated vulnerabilities

5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.

CVE-2025-8088WinRAR Windows Path Traversal via NTFS Alternate Data StreamsIn the wildEvidence6

The XHTML then uses HTML smuggling to deliver a RAR archive that exploits CVE-2025-8088, a critical path traversal flaw in WinRAR patched in version 7.13.

CVE-2025-6218RARLAB WinRAR Directory Traversal Remote Code Execution VulnerabilityIn the wildEvidence3

Indicators of Compromise (IoCs):- ... CVE-2025-6218 WinRAR vulnerability used by Gamaredon/Sandworm/RomCom

CVE-2025-9491Microsoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityIn the wildEvidence2

This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.

CVE-2017-0199Microsoft Office/WordPad Remote Code Execution VulnerabilityIn the wildEvidence1

Документи ... містили шкідливий код для експлуатації відомої вразливості «Microsoft Office» CVE-2017-0199 ... що надає змогу зловмиснику виконати довільний код на пристрої користувача, при відкритті інфікованого файлу.

CVE-2018-20250WinRAR ACE archive path traversal arbitrary file writeIn the wildEvidence1

Interestingly, the SSU documented Gamaredon leveraging this same TTP as early as 2018 exploiting CVE-2018-20250.

IOCS

Observables

204 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

security affairsNews
Jun 4, 2026
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

Cyberespionage activity focused on Ukrainian targets using a modular, nearly fileless infection chain that exploits a WinRAR vulnerability for initial access, stages payloads with VBScript loaders, propagates via USB drives and network shares, and supports data theft and destructive capabilities.

Read more
cysecurity newsNews
Jun 3, 2026
Russian State-sponsored Hackers Attack Ukraine, Exploit WinRAR to Install Malware - CySecurity News - Latest Information Security and Hacking Incidents

Conducting espionage-oriented intrusions against Ukraine by exploiting a WinRAR vulnerability and deploying multiple malware families for host fingerprinting, persistence, propagation, data theft, and potentially destructive actions.

Read more
the hacker newsNews
Jun 2, 2026
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Russian state-sponsored espionage activity exploiting a WinRAR path traversal flaw to deliver GammaPhish, GammaLoad, GammaWorm, GammaSteel, and potentially GammaWipe for host fingerprinting, persistence, propagation, and data theft, primarily against Ukrainian targets.

Read more
malware newsNews
Jun 2, 2026
LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine - Malware Analysis - Malware Analysis, News and Indicators

An active espionage group targeting Ukraine that uses spearphishing, lightweight custom tooling, and rapid operations to compromise military and government organizations, and in 2025 facilitated Turla’s access to already compromised Ukrainian targets.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping40

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal41

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs5

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables204

Domains, IPs, and hashes tied to this actor, refreshed continuously.