Threat group.View on attack.mitre.org
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.
In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.
| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings. |
| T1005 Data from Local System |
Gamaredon Group has collected files from infected systems and uploaded them to a C2 server. |
| T1012 Query Registry |
Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. |
| T1016.001 Internet Connection Discovery |
Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status. |
| T1020 Automated Exfiltration |
Gamaredon Group has used modules that automatically upload gathered documents to the C2 server. |
| T1021.005 VNC |
Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts. |
| T1025 Data from Removable Media |
A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives. |
| T1027 Obfuscated Files or Information |
Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file. |
| T1027.004 Compile After Delivery |
Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in |
| T1027.010 Command Obfuscation |
Gamaredon Group has used obfuscated or encrypted scripts. |
| T1027.012 LNK Icon Smuggling |
Gamaredon Group has used LNK files to hide malicious scripts for execution. |
| T1027.015 Compression |
Gamaredon Group has delivered malicious payloads within compressed archives and zip files. |
| T1027.016 Junk Code Insertion |
Gamaredon Group has obfuscated .NET executables by inserting junk code. |
| T1033 System Owner/User Discovery |
A Gamaredon Group file stealer can gather the victim's username to send to a C2 server. |
| T1036.005 Match Legitimate Resource Name or Location |
Gamaredon Group has used legitimate process names to hide malware including |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.