Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains
Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) (TL-2026-1484), also tracked as ACTINIUM Infrastructure Expansion, is a medium-severity tracked threat-actor profile, first published 2026-07-18. It is attributed to Gamaredon Group (Russia) with high confidence, affects N/A Ukrainian government, military, judiciary, law enforcement, and, maps to 78 MITRE ATT&CK techniques (T1001, T1005, T1008), and is covered by 9 detection rules and 39 indicators of compromise.
Key facts for TL-2026-1484
- Threat ID
- TL-2026-1484
- Also known as
- ACTINIUM Infrastructure Expansion, Gamaredon Passive DNS Pivot 2024
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_ACTOR
- First published
- 2026-07-18
- Last reviewed
- 2026-07-18
- Attribution
- Gamaredon Group
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, military, judiciary, police - law enforcement, non-profit organisation, ngo
- Target regions
- ukraine, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 39
Malware and tooling in Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)
Malware and tooling: DesertDown, DilongTrash, DinoTrain, ObfuBerry, ObfuMerry, PowerPunch - S0685, Pteranodon/Pterodo, QuietSieve - S0686, Remcos, UltraVNC, ngrok - S0508
Independent researchers used Validin passive-DNS pivoting on the 124 domains Microsoft (MSTIC) attributed to ACTINIUM/Gamaredon in its February 2022 report to identify 122 additional .ru domains sharing the pivot IP 139.180.174[.]234, a coordinated July 27, 2022 registration/resolution cluster, and algorithmically-generated subdomain wordlist patterns consistent with confirmed ACTINIUM infrastructure.
How Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) works
ACTINIUM (aka Gamaredon Group, Primitive Bear, IRON TILDEN, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew; MITRE ATT&CK G0047) is a Russia-nexus cyber-espionage actor active since at least 2013 and publicly attributed by the Ukrainian government in November 2021 to the Russian Federal Security Service (FSB) Center 18, operating out of Crimea/Sevastopol. The group has maintained a near-decade-long campaign against Ukrainian government, military, judiciary, law enforcement, and non-profit organizations, prioritizing intelligence collection and exfiltration over destructive impact, while periodically supporting disk-wipe/defacement capability alongside its core espionage tradecraft.
On February 4, 2022, Microsoft's MSTIC published a detailed report on ACTINIUM (then tracked as DEV-0157) documenting spear-phishing-driven intrusions using malicious macro documents with remote template injection, and enumerated a set of infrastructure indicators including domains, IPs, and file hashes for the group's malware families (Pteranodon/Pterodo, PowerPunch, QuietSieve, ObfuBerry, ObfuMerry, DilongTrash, DinoTrain, DesertDown). Independent tri-vendor tracking (Microsoft, Palo Alto Networks, Symantec) around the same period produced a combined pool of 151 unique domains attributed to the group.
On March 30, 2024, Embee Research published a passive-DNS pivoting analysis (using the Validin platform and CyberChef for indicator extraction) that bulk-resolved the 124 Microsoft-reported domains, yielding roughly 20,402 raw DNS indicators. Frequency analysis of the resulting IP set identified 139.180.174[.]234 as the single most reused hosting IP, appearing across 49 of the 124 original domains, with a pronounced resolution spike around July 27, 2022 indicating a coordinated infrastructure deployment/rotation event. Pivoting on that IP and the July 27, 2022 temporal cluster, then filtering to the .ru TLD and extracting primary (registrable) domains from the associated subdomain sets, the researchers derived a set-difference of 122 additional .ru domains not present in Microsoft's original disclosure but sharing the same hosting IP, registration-date clustering, and randomized-wordlist subdomain generation convention (each parent domain hosts numerous algorithmically-named subdomains drawn from an English wordlist) that Microsoft and ESET have separately documented as an ACTINIUM/Gamaredon operational signature. The researchers explicitly caveat that the pivot examined only a single IP address and that some results may be false positives, meaning further undiscovered infrastructure likely exists via other IP or ASN pivots.
This expansion is consistent with ACTINIUM's documented high-tempo infrastructure churn: Microsoft's original report and follow-on vendor tracking (e.g., CIRCLEID's April 2022 infrastructure analysis) describe the group registering 25+ new domains and 80+ unique IPs monthly, favoring ASN 197695 (REG.RU) and the REG.RU registrar, with DNS records changing roughly daily — a pattern that renders point-in-time domain lists rapidly stale and motivates continuous passive-DNS-based hunting of the type performed in this research. Subsequent ESET reporting on Gamaredon's 2024-2025 activity confirms the group's continued evolution, including hiding C2 infrastructure behind Cloudflare tunnels/workers, abusing third-party services (Telegram, Telegraph, Dropbox, Mastodon, DEV Community) as dead-drop resolvers, and upgrading file-stealer tooling (PteroPSDoor, PteroVDoor) to exfiltrate to S3-compatible object storage (Wasabi, Tebi, Intercolo) — underscoring that the domain set documented here represents one historical snapshot (July 2022 cluster) within a long-running, still-active infrastructure lifecycle rather than the totality of current ACTINIUM/Gamaredon assets.
No CVE or software exploitation is involved in this activity; ACTINIUM's initial access relies on spear-phishing with malicious macro/template-injection documents rather than vulnerability exploitation. This record documents an infrastructure-hunting/OSINT finding that materially expands blocklist and detection coverage for a nation-state espionage actor's historical (2022) domain footprint.
MITRE ATT&CK techniques used in TL-2026-1484
Command and Control
T1001 Data Obfuscation; T1008 Fallback Channels; T1071.001 Web Protocols; T1090 Proxy; T1090.003 Multi-hop Proxy; T1095 Non-Application Layer Protocol; T1102 Web Service; T1102.002 Bidirectional Communication; T1102.003 One-Way Communication; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution; T1568.001 Fast Flux DNS; T1571 Non-Standard Port
Collection
T1005 Data from Local System; T1025 Data from Removable Media; T1039 Data from Network Shared Drive; T1056.001 Keylogging; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection; T1123 Audio Capture; T1125 Video Capture
Discovery
T1010 Application Window Discovery; T1012 Query Registry; T1016.001 Internet Connection Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery; T1518.001 Security Software Discovery
Exfiltration
T1020 Automated Exfiltration; T1030 Data Transfer Size Limits; T1041 Exfiltration Over C2 Channel
Lateral Movement
T1021.005 VNC; T1534 Internal Spearphishing
Defense Evasion
T1027 Obfuscated Files or Information; T1027.004 Compile After Delivery; T1027.010 Command Obfuscation; T1027.012 LNK Icon Smuggling; T1027.015 Compression; T1027.016 Junk Code Insertion; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1497.001 System Checks; T1564.003 Hidden Window; T1620 Reflective Code Loading
Execution
T1047 Windows Management Instrumentation; T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1106 Native API; T1204.001 Malicious Link; T1204.002 Malicious File; T1559.001 Component Object Model
lateral-movement
T1080 Taint Shared Content; T1091 Replication Through Removable Media
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Persistence
T1137 Office Application Startup; T1547.001 Registry Run Keys / Startup Folder
stealth
T1218.005 Mshta; T1218.011 Rundll32; T1221 Template Injection
Impact
T1491.001 Internal Defacement; T1561.001 Disk Content Wipe
Privilege Escalation
T1548.002 Bypass User Account Control
Initial Access
T1566.001 Spearphishing Attachment
resource-development
T1583.001 Domains; T1583.003 Virtual Private Server
Resource Development
T1587.003 Digital Certificates; T1588.002 Tool; T1608.001 Upload Malware
Affected products and versions in Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)
- N/A — Ukrainian government, military, judiciary, law enforcement, and non-profit organizations (ACTINIUM/Gamaredon targeting scope)
Remediation for Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)
Immediate actions
- Block/sinkhole the pivot IP 139.180.174.234 and all 122 newly identified .ru domains at DNS/perimeter firewall layers
- Add the 122 domains and known Microsoft-reported 124-domain set to threat-intel blocklists and SIEM watchlists
- Hunt historical DNS/proxy logs for resolutions to 139.180.174.234 or any listed domain since July 2022
- Flag any observed connections for incident-response triage given the espionage-focused nature of this actor
Workarounds
- Restrict outbound resolution/connectivity to .ru TLDs from environments with no legitimate business need, subject to organizational policy
Longer-term hardening
- Deploy passive-DNS-based infrastructure hunting (Validin, RiskIQ/PassiveTotal, or equivalent) to continuously pivot on known ACTINIUM hosting IPs and ASN 197695 (REG.RU)
- Implement detection for algorithmically-generated wordlist subdomains characteristic of Gamaredon infrastructure
- Deploy Microsoft Defender/Sentinel ACTINIUM hunting queries and keep signatures current given the group's near-daily DNS churn
- Monitor for Gamaredon's evolving 2024-2025 tradecraft: Cloudflare tunnel/worker-fronted C2, Telegram/Telegraph/Dropbox/Mastodon dead-drop abuse, and S3-compatible exfiltration endpoints (Wasabi, Tebi, Intercolo)
Timeline of Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)
- Gamaredon Group (ACTINIUM) begins operations against Ukrainian targets, per MITRE ATT&CK G0047 tracking.
- Ukrainian government publicly attributes Gamaredon to the Russian FSB, Center 18, tied to offices in Crimea and Sevastopol.
- Microsoft MSTIC publishes the ACTINIUM (DEV-0157) report, disclosing 124 domain indicators and detailing spear-phishing/macro-based targeting of Ukrainian government, military, judiciary, law enforcement, and NGO organizations.
- CIRCLEID publishes a follow-on infrastructure analysis revealing additional ACTINIUM/Gamaredon artifacts, describing monthly registration of 25+ domains and 80+ unique IPs with near-daily DNS churn.
- Passive-DNS data shows a coordinated resolution spike/deployment cluster centered on pivot IP 139.180.174.234, later identified by researchers as the key temporal marker for the newly-discovered 122-domain set.
- Embee Research publishes 'Uncovering APT Infrastructure with Passive DNS Pivoting,' using Validin and CyberChef to bulk-resolve the 124 Microsoft-reported domains (~20,402 indicators), identify 139.180.174.234 as the top-reused IP, and derive 122 previously-undisclosed .ru domains sharing the same IP, registration-date cluster, and subdomain wordlist pattern.
- ESET publishes 'Gamaredon in 2024,' documenting the group's continued spearphishing operations and evolved toolset, including C2 infrastructure increasingly hidden behind Cloudflare tunnels.
- ESET publishes 'Gamaredon in 2025,' documenting further infrastructure evolution: tunnels, workers, DDNS/PaaS-fronted C2, dead-drop resolvers via Telegram/Telegraph/Dropbox/Mastodon, and new PowerShell tools (PteroDee, PteroCache, PteroDum, PteroOdd, PteroPaste, PteroEffigy) alongside S3-compatible exfiltration via PteroPSDoor/PteroVDoor.
- This threat record documents the Embee Research passive-DNS pivot findings for defensive blocklist and detection expansion.
Sources cited for Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)
- Uncovering APT Infrastructure with Passive DNS Pivoting
- ACTINIUM targets Ukrainian organizations
- Microsoft Uncovers New Details of Russian Hacking Campaign Targeting Ukraine
- A Look at Actinium/Gamaredon's Infrastructure: More Artifacts Revealed
- Cyber threat activity in Ukraine: analysis and resources
- Gamaredon Group, G0047 - MITRE ATT&CK
- Gamaredon in 2024: Cranking out spearphishing campaigns against Ukraine with an evolved toolset
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
- Microsoft discloses new details on Russian hacker group Gamaredon
- ACTINIUM threat actors target organizations in Ukraine
Threats related to Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088
Detection coverage for TL-2026-1484
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1484 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.