Description
Gamaredon is a threat group associated with Russian intelligence that has run relentless campaigns against Ukrainian organizations since at least 2013. Its tooling includes fast moving downloaders, USB spreaders, and backdoors that provide file theft and remote access, and the group rebuilds infrastructure constantly to survive takedowns. Volume rather than stealth defines its approach, and its tools frequently serve as an initial access layer for other intrusion crews.
Stats
- First seen
- May 2022
- Last seen
- September 2026
Alert name variants
| Alert Name |
|---|
| Archive.Trojan.Gamaredon |
| Binary.Trojan.Gamaredon |
| ByteCode-MSIL.Trojan.Gamaredon |
| Document-HTML.Dropper.Gamaredon |
| Document-HTML.Trojan.Gamaredon |
| Email-MIME.Trojan.Gamaredon |
| MacOS.Dropper.Gamaredon |
| Script-BAT.Browser.Gamaredon |
| Script-BAT.Trojan.Gamaredon |
| Script-JS.Trojan.Gamaredon |
