Gamaredon Group

APT / StateG0047 ↗
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)70
SourceMITRE ATT&CK
Target categories: Government
Targeted regions: Ukraine · Germany
Also known as:ACTINIUMActiniumAqua BlizzardArmageddonBlue OtsoBlueAlphaDEV-0157G0047IRON TILDENNastyShrewPRIMITIVE BEARPrimitive BearShuckwormTrident UrsaUAC-0010Winterflounder

About the group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity59
Impact: High
T1566.001T1047T1137T1012T1005T1020ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceOffice ApplicationStartupDISCDiscoveryQuery RegistryCOLLCollectionData from LocalSystemEXFILExfiltrationAutomatedExfiltrationIMPACTImpactInternalDefacement

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 70

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 1287

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.128.234.124:443Remcosthreatfox
ip:port198.135.49.110:4489Remcosthreatfox
ip:port37.120.206.165:60507Remcosthreatfox
ip:port103.83.87.86:2404Remcosthreatfox
ip:port185.149.24.115:2404Remcosthreatfox
ip:port128.90.108.225:2424Remcosthreatfox
ip:port103.83.86.40:14642Remcosthreatfox
ip:port31.59.137.81:4565Remcosthreatfox
domainjustily.duckdns.orgRemcosthreatfox
ip:port128.90.108.89:2424Remcosthreatfox
ip:port103.254.61.170:3889Remcosthreatfox
ip:port194.116.236.83:15800Remcosthreatfox
ip:port46.246.14.21:5987Remcosthreatfox
ip:port204.44.93.119:7878Remcosthreatfox
ip:port128.90.108.50:2424Remcosthreatfox
ip:port128.90.102.194:2015Remcosthreatfox
ip:port43.228.157.72:1208Remcosthreatfox
ip:port102.220.163.130:14644Remcosthreatfox
ip:port128.90.108.109:2405Remcosthreatfox
ip:port84.32.41.212:443Remcosthreatfox
ip:port194.116.236.83:2404Remcosthreatfox
ip:port194.116.236.83:15700Remcosthreatfox
ip:port185.214.10.188:2404Remcosthreatfox
ip:port172.111.137.68:65070Remcosthreatfox
ip:port155.103.71.210:55280Remcosthreatfox
ip:port78.40.209.168:2404Remcosthreatfox
domainwww.mrfixitmrfixitlocalplcbackup.comRemcosthreatfox
domainwww.mrfixitmrfixitlocalplc1.comRemcosthreatfox
domainwww.mrfixitmrfixitlocalplc.comRemcosthreatfox
ip:port172.111.137.69:65070Remcosthreatfox

+1287 indicators in total. See them all on the IOCs page.

Gamaredon Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →