# Gamaredon

> As of 2026-08-26, Gamaredon is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning campaign, threat actor, vulnerability. Also known as Aqua Blizzard, Gamaredon Group, UAC-0010, Shuckworm. ATT&CK coverage spans 120 techniques across 14 tactics in 7 of 7 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1102 (Web Service).

- **Nation:** Russia
- **Tracked threats:** 7
- **Categories:** CAMPAIGN, THREAT_ACTOR, VULNERABILITY, APT, MALWARE, PHISHING
- **Also known as:** Aqua Blizzard, Gamaredon Group, UAC-0010, Shuckworm, Primitive Bear, Armageddon, ACTINIUM, Trident Ursa, BlueAlpha, IRON TILDEN, Winterflounder
- **As of:** 2026-08-26

## ATT&CK techniques observed

120 techniques observed across 7 of 7 tracked threats. Tactics: Stealth (formerly Defense Evasion) (26), Command and Control (14), Resource Development (13), Execution (11), Discovery (10), Persistence (10).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 7 of 7 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 5 of 7 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 5 of 7 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 5 of 7 tracked threats
- [T1025](https://intel.threadlinqs.com/technique/T1025) Data from Removable Media — Collection — observed in 4 of 7 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 4 of 7 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 4 of 7 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 4 of 7 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 4 of 7 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 4 of 7 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 4 of 7 tracked threats
- [T1091](https://intel.threadlinqs.com/technique/T1091) Replication Through Removable Media — Initial Access — observed in 4 of 7 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 4 of 7 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 4 of 7 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 4 of 7 tracked threats

## Tracked threats

- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-1287) — MEDIUM
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)](https://intel.threadlinqs.com/threat/TL-2026-1210) — HIGH
- [Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088](https://intel.threadlinqs.com/threat/TL-2026-1216) — HIGH
- [Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)](https://intel.threadlinqs.com/threat/TL-2026-0968) — HIGH
- [Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations](https://intel.threadlinqs.com/threat/TL-2026-0723) — HIGH
- [Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access](https://intel.threadlinqs.com/threat/TL-2026-0653) — HIGH
- [Screensaver (.SCR) Files Used as Initial Access Vector](https://intel.threadlinqs.com/threat/TL-2026-0104) — HIGH

## Related CVEs

2 CVEs referenced by tracked Gamaredon activity.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Gamaredon
