PRIMITIVE BEAR
SHUCKWORM
ARMAGEDDON
UAC-0010
Threat IntelligenceAPTFebruary 20, 202615 min read

Gamaredon: Threat Intelligence Profile

Russian FSB-linked APT from occupied Crimea conducting high-volume, persistent espionage operations against Ukrainian government and military organizations.

Scroll

Gamaredon / Primitive Bear (also known as Primitive Bear, Shuckworm, Armageddon, UAC-0010) is a state-sponsored advanced persistent threat group attributed to Russia (FSB, Crimea), active since 2013. The group primarily targets Ukraine government, military, law enforcement sectors. It is tracked by MITRE ATT&CK as G0047.

Overview & Attribution

Russian FSB-linked APT from occupied Crimea conducting high-volume, persistent espionage operations against Ukrainian government and military organizations.

Threat Assessment

Gamaredon has been active since 2013, attributed to Russia (FSB, Crimea). The group is known for targeting Ukraine government, military, law enforcement using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

Gamaredon employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on Ukraine government, military, law enforcement sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

Gamaredon is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentMass spearphishing campaigns
ExecutionT1059.005 Visual BasicVBS/VBA macro chains
PersistenceT1547.001 Registry Run KeysRegistry persistence
Defense EvasionT1027 Obfuscated FilesHeavy script obfuscation
CollectionT1005 Data from Local SystemDocument harvesting
C2T1071.001 Web ProtocolsHTTP C2 with fast flux DNS

Notable Campaigns

Gamaredon has been linked to multiple significant campaigns targeting Ukraine government, military, law enforcement organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against Gamaredon

Mjolnir Security provides specialized capabilities to detect and respond to Gamaredon operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for Gamaredon TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of Gamaredon campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: February 20, 2026