Gamaredon

☆ pin
MITRE G0047Also known as Earth Dahu, Primitive Bear, Shuckworm, Aqua Blizzard, UAC-0010, BlueAlpha, ACTINIUM
Reports
9
First seen
Oct 1, 2025
Last seen
Jun 29, 2026
Motivation
Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×7
×7
Ukraine×7

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566 Phishing ×7T1059.001 PowerShell ×5T1041 Exfiltration Over C2 Channel ×5T1005 Data from Local System ×5T1190 Exploit Public-Facing Application ×4T1547.001 Registry Run Keys / Startup Folder ×4T1566.001 Phishing: Spearphishing Attachment ×4T1059.005 Command and Scripting Interpreter: Visual Basic ×3T1071.001 Application Layer Protocol: Web Protocols ×3T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage ×3T1547 Boot or Logon Autostart Execution ×2T1564.004 Hide Artifacts: NTFS File Attributes ×2

Indicators

domain ×38cve ×17ip_v4 ×9filename ×8email ×2hash_sha256 ×1url ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.