Gamaredon Group

APT / StateG0047
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)70
SourceMITRE ATT&CK
Target categories: Government
Targeted regions: Ukraine · Germany
Also known as:ACTINIUMActiniumAqua BlizzardArmageddonBlue OtsoBlueAlphaDEV-0157G0047IRON TILDENNastyShrewPRIMITIVE BEARPrimitive BearShuckwormTrident UrsaUAC-0010Winterflounder

Vexday analysis

Gamaredon Group é um grupo suspeito de espionagem cibernética de origem russa que atua contra organizações militares, de segurança pública, do judiciário, sem fins lucrativos e não governamentais na Ucrânia desde pelo menos 2013. Em novembro de 2021, o governo ucraniano atribuiu publicamente o grupo ao Centro 18 do Serviço Federal de Segurança da Rússia (FSB), avaliação posteriormente corroborada por múltiplos pesquisadores independentes de segurança. Registrado no MITRE ATT&CK como G0047, o grupo é rastreado sob os aliases IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm e DEV-0157, com 70 técnicas documentadas na base de conhecimento.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity59
Impact: High
T1566.001T1047T1137T1012T1005T1020ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceOffice ApplicationStartupDISCDiscoveryQuery RegistryCOLLCollectionData from LocalSystemEXFILExfiltrationAutomatedExfiltrationIMPACTImpactInternalDefacement

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 70

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 466

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port103.83.87.87:26900Remcosthreatfox
ip:port103.83.87.87:22300Remcosthreatfox
ip:port103.83.87.87:27900Remcosthreatfox
ip:port103.83.87.87:24900Remcosthreatfox
domainwhichkindwahalabethisonesooluwahelurboi.duckdns.orgRemcosthreatfox
ip:port155.103.69.20:14647Remcosthreatfox
domaineventras.duckdns.orgRemcosthreatfox
ip:port107.175.88.92:2404Remcosthreatfox
ip:port87.120.244.219:13131Remcosthreatfox
ip:port77.110.108.14:9001Remcosthreatfox
ip:port80.97.160.237:23401Remcosthreatfox
ip:port91.193.7.162:13309Remcosthreatfox
ip:port185.91.126.112:443Remcosthreatfox
ip:port45.74.3.160:2404Remcosthreatfox
ip:port144.24.14.113:7005Remcosthreatfox
ip:port104.251.181.148:1427Remcosthreatfox
ip:port185.116.238.123:8088Remcosthreatfox
ip:port15.204.115.143:2404Remcosthreatfox
ip:port104.251.181.148:443Remcosthreatfox
ip:port104.251.181.148:80Remcosthreatfox
ip:port185.91.126.107:443Remcosthreatfox
domainxoso6640.comRemcosthreatfox
domainaseguradora2026.kozow.comRemcosthreatfox
domain2301amarilloa.kozow.comRemcosthreatfox
domainnordking.spaceRemcosthreatfox
domainnordkingbackup.spaceRemcosthreatfox
domaincreatifanay.duckdns.orgRemcosthreatfox
domaincrushanytics.duckdns.orgRemcosthreatfox
domainnordkingbackup1.spaceRemcosthreatfox
domainnordkingbackup2.spaceRemcosthreatfox

+466 indicators in total. See them all on the IOCs page.

Gamaredon Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →