FlagThis
← Threat Actors
/
Russia
/
Gamaredon
DOSSIER // GAMAREDON
Gamaredon
▲ High Threat
Russia
Primary Aliases:
Primitive Bear
ACTINIUM
Armageddon
Shuckworm
🔍 Adversary Rosetta Stone (4) ▾
📋 Copy All
Sponsor / State Affiliation
FSB (Federal Security Service)
Primary Motivation
Espionage, Sabotage (Ukraine-focused)
Active Timeline
2013 – Present
Confidence Rating
70% (Grounded)
Most active APT targeting Ukraine, over 5000 phishing attacks against Ukrainian entities
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🛡️ MITRE ATT&CK (G0047) ↗
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(2)
CVE-2017-0199
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
CVE-2017-11882
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
📋 Copy CSV
Tenable Nessus
Qualys / Wiz
🎯 Target Sectors & Focus
Ukraine government
Military
NGOs
Law enforcement
🛡️ MITRE ATT&CK® Attack Lifecycle
(5 TTPs)
📥 Download Navigator JSON
All Stages
5
Initial Access
1
Credential Access & Discovery
1
Command & Control
1
Operational Techniques
2
Initial Access
1
T1566
Spear-phishing
↗
Credential Access & Discovery
1
T1003
Credential harvesting
↗
Command & Control
1
T1071
Pterodo backdoor
↗
Operational Techniques
2
T1000
USB worms
↗
T1000
High-volume low-sophistication attacks
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Russian State-Sponsored Deployment of StockStay and SharkLoader
Attacks and Vulnerabilities
2026-07-03
Adversary Rosetta Stone // Gamaredon
×
🪟 Microsoft Threat Actor Naming
ACTINIUM
📋
🦅 CrowdStrike Monikers
Primitive Bear
📋
🛡️ Other Industry Tracking Codes
Armageddon
📋
Shuckworm
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD