Netskope Threat Labs

Gamaredon

ATP Sandbox Adv. HeuristicsNetskope IPS

Gamaredon is a threat group associated with Russian intelligence that has run relentless campaigns against Ukrainian organizations since at least 2013. Its tooling includes fast moving downloaders, USB spreaders, and backdoors that provide file theft and remote access, and the group rebuilds infrastructure constantly to survive takedowns. Volume rather than stealth defines its approach, and its tools frequently serve as an initial access layer for other intrusion crews.

First seen
May 2022
Last seen
September 2026
Alert Name
Archive.Trojan.Gamaredon
Binary.Trojan.Gamaredon
ByteCode-MSIL.Trojan.Gamaredon
Document-HTML.Dropper.Gamaredon
Document-HTML.Trojan.Gamaredon
Email-MIME.Trojan.Gamaredon
MacOS.Dropper.Gamaredon
Script-BAT.Browser.Gamaredon
Script-BAT.Trojan.Gamaredon
Script-JS.Trojan.Gamaredon