Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-06

Gamaredon Group

Also known as:ACTINIUM

As of 2026-07-18, Gamaredon Group is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat actor, apt. Also known as ACTINIUM. ATT&CK coverage spans 98 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1012 (Query Registry), T1025 (Data from Removable Media).

Tracked threats
21 high · 1 medium
First seen
2026-06-28
Last seen
2026-07-18
ATT&CK techniques
98across 2 of 2 threats
Related CVEs
1Referenced by its activity
Attribution
RussiaNation or origin
Nation: Russia · 2 tracked threat(s) · Categories: THREAT_ACTOR, APT

Activity timeline

Gamaredon Group appears in 2 tracked threats between and ; the busiest month was 2026-06 with 1 report.

ATT&CK techniques observed

98 techniques observed across 2 of 2 tracked threats · Stealth (formerly Defense Evasion) (21), Command and Control (15), Discovery (11), Execution (11), Collection (9), Resource Development (8)
  • T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
  • T1012 Query Registry — Discoveryobserved in 2 of 2 tracked threats
  • T1025 Data from Removable Media — Collectionobserved in 2 of 2 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1080 Taint Shared Content — Lateral Movementobserved in 2 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1090 Proxy — Command and Controlobserved in 2 of 2 tracked threats
  • T1091 Replication Through Removable Media — Lateral Movementobserved in 2 of 2 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 2 tracked threats
  • T1135 Network Share Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1480 Execution Guardrails — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1568 Dynamic Resolution — Command and Controlobserved in 2 of 2 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Gamaredon Group activity