Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings.8
group
Gamaredon Group G0047
- Created
- 31 May 2017
- Last modified
- 31 July 2026
- Aliases
- Gamaredon Group · IRON TILDEN · Primitive Bear · ACTINIUM · Armageddon · Shuckworm · DEV-0157 · Aqua Blizzard · NastyShrew
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]
In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][7]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0047
Gamaredon Group has collected files from infected systems and uploaded them to a C2 server.910
Gamaredon Group has queried HKEY_CURRENT_USER\\Console\\WindowsUpdates to obtain the C2 addresses.11 Gamaredon Group has queried HKEY_CURRENT_USER\\Console\\WindowsUpdates to obtain the C2 addresses.11
Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as CSIDL_SYSTEM\cmd.exe /c ping -n 1.13 Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status.14
Gamaredon Group has used modules that automatically upload gathered documents to the C2 server.15
Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.161718
Standing G0047
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
94th percentile · 94% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
85th percentile · 85% of 176 ATT&CK groups have this many tactics spanned or fewer.
67th percentile · 67% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
23rd percentile · 77% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0047
1826 distinct rules cover the 70 techniques recorded for this group. The 2159 technique-to-rule mappings resolve to 1826 distinct rules, because one rule can cover several techniques. 1201 Sigma · 625 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org