Gamaredon Group is a cyber threat actor active since 2013, primarily targeting Ukrainian government entities.
Analyst brief
Gamaredon Group (also known as ACTINIUM, PRIMITIVE BEAR) has been active since at least 2013, primarily targeting government entities in Ukraine. They use spearphishing attachments for initial access and distribute custom-developed malware like QuietSieve and PowerPunch, reflecting improved technical capabilities. Observed TTPs include WMI for execution, Registry Run Keys for persistence, lateral movement via Removable Media, automated collection and exfiltration, and Non-Application Layer Protocol for C2. Defenders should prioritize email filtering, monitor WMI and registry modifications, control USB usage, and analyze network traffic for custom C2 patterns to detect this group's activity.
Gamaredon Group
ACTINIUMDEV-0157Blue Otso
unknown
Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon Group and our research shows that the Gamaredon Group has been active since at least 2013. In the past, the Gamaredon Group has relied heavily on off-the-shelf tools. Our new research shows the Gamaredon Group have made a shift to custom-developed malware. We believe this shift indicates the Gamaredon Group have improved their technical capabilities.