Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains

Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) (TL-2026-1484), also tracked as ACTINIUM Infrastructure Expansion, is a medium-severity tracked threat-actor profile, first published 2026-07-18. It is attributed to Gamaredon Group (Russia) with high confidence, affects N/A Ukrainian government, military, judiciary, law enforcement, and, maps to 78 MITRE ATT&CK techniques (T1001, T1005, T1008), and is covered by 9 detection rules and 39 indicators of compromise.

Key facts for TL-2026-1484

Threat ID
TL-2026-1484
Also known as
ACTINIUM Infrastructure Expansion, Gamaredon Passive DNS Pivot 2024
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_ACTOR
First published
2026-07-18
Last reviewed
2026-07-18
Attribution
Gamaredon Group
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, military, judiciary, police - law enforcement, non-profit organisation, ngo
Target regions
ukraine, 151 - Eastern Europe
Detection rules
9
Indicators of compromise
39

Malware and tooling in Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)

Malware and tooling: DesertDown, DilongTrash, DinoTrain, ObfuBerry, ObfuMerry, PowerPunch - S0685, Pteranodon/Pterodo, QuietSieve - S0686, Remcos, UltraVNC, ngrok - S0508

Independent researchers used Validin passive-DNS pivoting on the 124 domains Microsoft (MSTIC) attributed to ACTINIUM/Gamaredon in its February 2022 report to identify 122 additional .ru domains sharing the pivot IP 139.180.174[.]234, a coordinated July 27, 2022 registration/resolution cluster, and algorithmically-generated subdomain wordlist patterns consistent with confirmed ACTINIUM infrastructure.

How Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) works

ACTINIUM (aka Gamaredon Group, Primitive Bear, IRON TILDEN, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew; MITRE ATT&CK G0047) is a Russia-nexus cyber-espionage actor active since at least 2013 and publicly attributed by the Ukrainian government in November 2021 to the Russian Federal Security Service (FSB) Center 18, operating out of Crimea/Sevastopol. The group has maintained a near-decade-long campaign against Ukrainian government, military, judiciary, law enforcement, and non-profit organizations, prioritizing intelligence collection and exfiltration over destructive impact, while periodically supporting disk-wipe/defacement capability alongside its core espionage tradecraft.

On February 4, 2022, Microsoft's MSTIC published a detailed report on ACTINIUM (then tracked as DEV-0157) documenting spear-phishing-driven intrusions using malicious macro documents with remote template injection, and enumerated a set of infrastructure indicators including domains, IPs, and file hashes for the group's malware families (Pteranodon/Pterodo, PowerPunch, QuietSieve, ObfuBerry, ObfuMerry, DilongTrash, DinoTrain, DesertDown). Independent tri-vendor tracking (Microsoft, Palo Alto Networks, Symantec) around the same period produced a combined pool of 151 unique domains attributed to the group.

On March 30, 2024, Embee Research published a passive-DNS pivoting analysis (using the Validin platform and CyberChef for indicator extraction) that bulk-resolved the 124 Microsoft-reported domains, yielding roughly 20,402 raw DNS indicators. Frequency analysis of the resulting IP set identified 139.180.174[.]234 as the single most reused hosting IP, appearing across 49 of the 124 original domains, with a pronounced resolution spike around July 27, 2022 indicating a coordinated infrastructure deployment/rotation event. Pivoting on that IP and the July 27, 2022 temporal cluster, then filtering to the .ru TLD and extracting primary (registrable) domains from the associated subdomain sets, the researchers derived a set-difference of 122 additional .ru domains not present in Microsoft's original disclosure but sharing the same hosting IP, registration-date clustering, and randomized-wordlist subdomain generation convention (each parent domain hosts numerous algorithmically-named subdomains drawn from an English wordlist) that Microsoft and ESET have separately documented as an ACTINIUM/Gamaredon operational signature. The researchers explicitly caveat that the pivot examined only a single IP address and that some results may be false positives, meaning further undiscovered infrastructure likely exists via other IP or ASN pivots.

This expansion is consistent with ACTINIUM's documented high-tempo infrastructure churn: Microsoft's original report and follow-on vendor tracking (e.g., CIRCLEID's April 2022 infrastructure analysis) describe the group registering 25+ new domains and 80+ unique IPs monthly, favoring ASN 197695 (REG.RU) and the REG.RU registrar, with DNS records changing roughly daily — a pattern that renders point-in-time domain lists rapidly stale and motivates continuous passive-DNS-based hunting of the type performed in this research. Subsequent ESET reporting on Gamaredon's 2024-2025 activity confirms the group's continued evolution, including hiding C2 infrastructure behind Cloudflare tunnels/workers, abusing third-party services (Telegram, Telegraph, Dropbox, Mastodon, DEV Community) as dead-drop resolvers, and upgrading file-stealer tooling (PteroPSDoor, PteroVDoor) to exfiltrate to S3-compatible object storage (Wasabi, Tebi, Intercolo) — underscoring that the domain set documented here represents one historical snapshot (July 2022 cluster) within a long-running, still-active infrastructure lifecycle rather than the totality of current ACTINIUM/Gamaredon assets.

No CVE or software exploitation is involved in this activity; ACTINIUM's initial access relies on spear-phishing with malicious macro/template-injection documents rather than vulnerability exploitation. This record documents an infrastructure-hunting/OSINT finding that materially expands blocklist and detection coverage for a nation-state espionage actor's historical (2022) domain footprint.

MITRE ATT&CK techniques used in TL-2026-1484

Command and Control

T1001 Data Obfuscation; T1008 Fallback Channels; T1071.001 Web Protocols; T1090 Proxy; T1090.003 Multi-hop Proxy; T1095 Non-Application Layer Protocol; T1102 Web Service; T1102.002 Bidirectional Communication; T1102.003 One-Way Communication; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution; T1568.001 Fast Flux DNS; T1571 Non-Standard Port

Collection

T1005 Data from Local System; T1025 Data from Removable Media; T1039 Data from Network Shared Drive; T1056.001 Keylogging; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection; T1123 Audio Capture; T1125 Video Capture

Discovery

T1010 Application Window Discovery; T1012 Query Registry; T1016.001 Internet Connection Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery; T1518.001 Security Software Discovery

Exfiltration

T1020 Automated Exfiltration; T1030 Data Transfer Size Limits; T1041 Exfiltration Over C2 Channel

Lateral Movement

T1021.005 VNC; T1534 Internal Spearphishing

Defense Evasion

T1027 Obfuscated Files or Information; T1027.004 Compile After Delivery; T1027.010 Command Obfuscation; T1027.012 LNK Icon Smuggling; T1027.015 Compression; T1027.016 Junk Code Insertion; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1497.001 System Checks; T1564.003 Hidden Window; T1620 Reflective Code Loading

Execution

T1047 Windows Management Instrumentation; T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1106 Native API; T1204.001 Malicious Link; T1204.002 Malicious File; T1559.001 Component Object Model

lateral-movement

T1080 Taint Shared Content; T1091 Replication Through Removable Media

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Persistence

T1137 Office Application Startup; T1547.001 Registry Run Keys / Startup Folder

stealth

T1218.005 Mshta; T1218.011 Rundll32; T1221 Template Injection

Impact

T1491.001 Internal Defacement; T1561.001 Disk Content Wipe

Privilege Escalation

T1548.002 Bypass User Account Control

Initial Access

T1566.001 Spearphishing Attachment

resource-development

T1583.001 Domains; T1583.003 Virtual Private Server

Resource Development

T1587.003 Digital Certificates; T1588.002 Tool; T1608.001 Upload Malware

Affected products and versions in Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)

  • N/A — Ukrainian government, military, judiciary, law enforcement, and non-profit organizations (ACTINIUM/Gamaredon targeting scope)

Remediation for Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)

Immediate actions

  • Block/sinkhole the pivot IP 139.180.174.234 and all 122 newly identified .ru domains at DNS/perimeter firewall layers
  • Add the 122 domains and known Microsoft-reported 124-domain set to threat-intel blocklists and SIEM watchlists
  • Hunt historical DNS/proxy logs for resolutions to 139.180.174.234 or any listed domain since July 2022
  • Flag any observed connections for incident-response triage given the espionage-focused nature of this actor

Workarounds

  • Restrict outbound resolution/connectivity to .ru TLDs from environments with no legitimate business need, subject to organizational policy

Longer-term hardening

  • Deploy passive-DNS-based infrastructure hunting (Validin, RiskIQ/PassiveTotal, or equivalent) to continuously pivot on known ACTINIUM hosting IPs and ASN 197695 (REG.RU)
  • Implement detection for algorithmically-generated wordlist subdomains characteristic of Gamaredon infrastructure
  • Deploy Microsoft Defender/Sentinel ACTINIUM hunting queries and keep signatures current given the group's near-daily DNS churn
  • Monitor for Gamaredon's evolving 2024-2025 tradecraft: Cloudflare tunnel/worker-fronted C2, Telegram/Telegraph/Dropbox/Mastodon dead-drop abuse, and S3-compatible exfiltration endpoints (Wasabi, Tebi, Intercolo)

Timeline of Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)

  • Gamaredon Group (ACTINIUM) begins operations against Ukrainian targets, per MITRE ATT&CK G0047 tracking.
  • Ukrainian government publicly attributes Gamaredon to the Russian FSB, Center 18, tied to offices in Crimea and Sevastopol.
  • Microsoft MSTIC publishes the ACTINIUM (DEV-0157) report, disclosing 124 domain indicators and detailing spear-phishing/macro-based targeting of Ukrainian government, military, judiciary, law enforcement, and NGO organizations.
  • CIRCLEID publishes a follow-on infrastructure analysis revealing additional ACTINIUM/Gamaredon artifacts, describing monthly registration of 25+ domains and 80+ unique IPs with near-daily DNS churn.
  • Passive-DNS data shows a coordinated resolution spike/deployment cluster centered on pivot IP 139.180.174.234, later identified by researchers as the key temporal marker for the newly-discovered 122-domain set.
  • Embee Research publishes 'Uncovering APT Infrastructure with Passive DNS Pivoting,' using Validin and CyberChef to bulk-resolve the 124 Microsoft-reported domains (~20,402 indicators), identify 139.180.174.234 as the top-reused IP, and derive 122 previously-undisclosed .ru domains sharing the same IP, registration-date cluster, and subdomain wordlist pattern.
  • ESET publishes 'Gamaredon in 2024,' documenting the group's continued spearphishing operations and evolved toolset, including C2 infrastructure increasingly hidden behind Cloudflare tunnels.
  • ESET publishes 'Gamaredon in 2025,' documenting further infrastructure evolution: tunnels, workers, DDNS/PaaS-fronted C2, dead-drop resolvers via Telegram/Telegraph/Dropbox/Mastodon, and new PowerShell tools (PteroDee, PteroCache, PteroDum, PteroOdd, PteroPaste, PteroEffigy) alongside S3-compatible exfiltration via PteroPSDoor/PteroVDoor.
  • This threat record documents the Embee Research passive-DNS pivot findings for defensive blocklist and detection expansion.

Sources cited for Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)

Threats related to Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon)

Detection coverage for TL-2026-1484

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1484 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats