Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains — Threadlinqs Intelligence
As of 2026-07-18, Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains is a medium-severity threat actor threat attributed to Gamaredon Group (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 39 indicators of compromise.
Threat ID: TL-2026-1484 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_ACTOR
Attribution: Gamaredon Group · Russia · ESPIONAGE
Independent researchers used Validin passive-DNS pivoting on the 124 domains Microsoft (MSTIC) attributed to ACTINIUM/Gamaredon in its February 2022 report to identify 122 additional .ru domains
ACTINIUM (aka Gamaredon Group, Primitive Bear, IRON TILDEN, Armageddon, Shuckworm, DEV-0157, Aqua Blizzard, NastyShrew; MITRE ATT&CK G0047) is a Russia-nexus cyber-espionage actor active since at least 2013 and publicly attributed by the Ukrainian government in November 2021 to the Russian Federal Security Service (FSB) Center 18, operating out of Crimea/Sevastopol. The group has maintained a near-decade-long campaign against Ukrainian government, military, judiciary, law enforcement, and non-profit organizations, prioritizing intelligence collection and exfiltration over destructive impact, while periodically supporting disk-wipe/defacement capability alongside its core espionage tradecraft.
On February 4, 2022, Microsoft's MSTIC published a detailed report on ACTINIUM (then tracked as DEV-0157) documenting spear-phishing-driven intrusions using malicious macro documents with remote template injection, and enumerated a set of infrastructure indicators including domains, IPs, and file hashes for the group's malware families (Pteranodon/Pterodo, PowerPunch, QuietSieve, ObfuBerry, ObfuMerry, DilongTrash, DinoTrain, DesertDown). Independent tri-vendor tracking (Microsoft, Palo Alto Networks, Symantec) around the same period produced a combined pool of 151 unique domains attributed to the group.
On March 30, 2024, Embee Research published a passive-DNS pivoting analysis (using the Validin platform and CyberChef for indicator extraction) that bulk-resolved the 124 Microsoft-reported domains, yielding roughly 20,402 raw DNS indicators. Frequency analysis of the resulting IP set identified 139.180.174[.]234 as the single most reused hosting IP, appearing across 49 of the 124 original domains, with a pronounced resolution spike around July 27, 2022 indicating a coordinated infrastructure deployment/rotation event. Pivoting on that IP and the July 27, 2022 temporal cluster, then filtering to the .ru TLD and extracting primary (registrable) domains from the associated subdomain sets, the researchers derived a set-difference of 122 additional .ru domains not present in Microsoft's original disclosure but sharing the same hosting IP, registration-date clustering, and randomized-wordlist subdomain generation convention (each parent domain hosts numerous algorithmically-named subdomains drawn from an English wordlist) that Microsoft and ESET have separately documented as an ACTINIUM/Gamaredon operational signature. The researchers explicitly caveat that the pivot examined only a single IP address and that some results may be false positives, meaning further undiscovered infrastructure likely exists via other IP or ASN pivots.
This expansion is consistent with ACTINIUM's documented high-tempo infrastructure churn: Microsoft's original report and follow-on vendor tracking (e.g., CIRCLEID's April 2022 infrastructure analysis) describe the group registering 25+ new domains and 80+ unique IPs monthly, favoring ASN 197695 (REG.RU) and the REG.RU registrar, with DNS records changing roughly daily — a pattern that renders point-in-time domain lists rapidly stale and motivates continuous passive-DNS-based hunting of the type performed in this research. Subsequent ESET reporting on Gamaredon's 2024-2025 activity confirms the group's continued evolution, including hiding C2 infrastructure behind Cloudflare tunnels/workers, abusing third-party services (Telegram, Telegraph, Dropbox, Mastodon, DEV Community) as dead-drop resolvers, and upgrading file-stealer tooling (PteroPSDoor, PteroVDoor) to exfiltrate to S3-compatible object storage (Wasabi, Tebi, Intercolo) — underscoring that the domain set documented here represents one historical snapshot (July 2022 cluster) within a long-running, still-active infrastructure lifecycle rather than the totality of current ACTINIUM/Gamaredon assets.
No CVE or software exploitation is involved in this activity; ACTINIUM's initial access relies on spear-phishing with malicious macro/template-injection documents r
Target sectors: government administration, military, judiciary, police - law enforcement, non-profit organisation, ngo
Target regions: ukraine, 151 - Eastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 39 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_ACTOR, MEDIUM, threat intelligence, cybersecurity, T1583.001, T1583.003, T1587.003, T1588.002, T1608.001, T1566.001, T1059.001, T1059.003, T1059.005, T1106