Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0047
MITRE ATT&CK Group

Gamaredon Group (G0047)

IRON TILDENPrimitive BearACTINIUMArmageddonShuckwormDEV-0157Aqua BlizzardNastyShrew
ShareXLinkedInRedditHN

[Gamaredon Group](https://attack.mitre.org/groups/G0047) is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name [Gamaredon Group](https://attack.mitre.org/groups/G0047) derives from a misspelling of the word "Armageddon," found in early campaigns.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: TrendMicro Gamaredon April 2020)(Citation: ESET Gamaredon June 2020)(Citation: Symantec Shuckworm January 2022)(Citation: Microsoft Actinium February 2022) In November 2021, the Ukrainian government publicly attributed [Gamaredon Group](https://attack.mitre.org/groups/G0047) to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. (Citation: Bleepingcomputer Gamardeon FSB November 2021)(Citation: Microsoft Actinium February 2022)

▪Techniques used (70)

T1491.001Internal DefacementT1583.003Virtual Private ServerT1001Data ObfuscationT1534Internal SpearphishingT1047Windows Management InstrumentationT1095Non-Application Layer ProtocolT1083File and Directory DiscoveryT1091Replication Through Removable MediaT1119Automated CollectionT1036.005Match Legitimate Resource Name or LocationT1027.004Compile After DeliveryT1105Ingress Tool TransferT1021.005VNCT1027.016Junk Code InsertionT1218.011Rundll32T1566.001Spearphishing AttachmentT1082System Information DiscoveryT1059.005Visual BasicT1113Screen CaptureT1518.001Security Software DiscoveryT1005Data from Local SystemT1039Data from Network Shared DriveT1608.001Upload MalwareT1027.015CompressionT1102.003One-Way CommunicationT1112Modify RegistryT1016.001Internet Connection DiscoveryT1620Reflective Code LoadingT1559.001Component Object ModelT1012Query RegistryT1025Data from Removable MediaT1221Template InjectionT1685Disable or Modify ToolsT1140Deobfuscate/Decode Files or InformationT1204.001Malicious LinkT1080Taint Shared ContentT1106Native APIT1583.006Web ServicesT1561.001Disk Content WipeT1033System Owner/User DiscoveryT1587.003Digital CertificatesT1564.003Hidden WindowT1027.012LNK Icon SmugglingT1070.004File DeletionT1059.001PowerShellT1571Non-Standard PortT1588.002ToolT1020Automated ExfiltrationT1071.001Web ProtocolsT1583.001DomainsT1568.001Fast Flux DNST1055Process InjectionT1120Peripheral Device DiscoveryT1041Exfiltration Over C2 ChannelT1090.003Multi-hop ProxyT1053.005Scheduled TaskT1027Obfuscated Files or InformationT1057Process DiscoveryT1027.010Command ObfuscationT1204.002Malicious FileT1568Dynamic ResolutionT1090ProxyT1547.001Registry Run Keys / Startup FolderT1480Execution GuardrailsT1102.002Bidirectional CommunicationT1059.003Windows Command ShellT1218.005MshtaT1137Office Application StartupT1102Web ServiceT1497.001System Checks

▪Software used (6)

S0686QuietSievemalwareS0147PteranodonmalwareS0332RemcostoolS0097PingtoolS0075RegtoolS0685PowerPunchmalware
G0047on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.