# Gamaredon Group

> As of 2026-07-18, Gamaredon Group is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat actor, apt. Also known as ACTINIUM. ATT&CK coverage spans 98 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1012 (Query Registry), T1025 (Data from Removable Media).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** THREAT_ACTOR, APT
- **Also known as:** ACTINIUM
- **As of:** 2026-07-18

## ATT&CK techniques observed

98 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (21), Command and Control (15), Discovery (11), Execution (11), Collection (9), Resource Development (8).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1012](https://intel.threadlinqs.com/technique/T1012) Query Registry — Discovery — observed in 2 of 2 tracked threats
- [T1025](https://intel.threadlinqs.com/technique/T1025) Data from Removable Media — Collection — observed in 2 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1080](https://intel.threadlinqs.com/technique/T1080) Taint Shared Content — Lateral Movement — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 2 of 2 tracked threats
- [T1091](https://intel.threadlinqs.com/technique/T1091) Replication Through Removable Media — Lateral Movement — observed in 2 of 2 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 2 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1480](https://intel.threadlinqs.com/technique/T1480) Execution Guardrails — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1568](https://intel.threadlinqs.com/technique/T1568) Dynamic Resolution — Command and Control — observed in 2 of 2 tracked threats

## Tracked threats

- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — MEDIUM
- [Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)](https://intel.threadlinqs.com/threat/TL-2026-0968) — HIGH

## Related CVEs

1 CVE referenced by tracked Gamaredon Group activity.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Gamaredon%20Group
