logo

Gamaredon_Group__2022__Microsoft_ACTINIUM-Ukrainian-organizations_02-04-2022.pdf

ID: 3feec283-60ca-4f11-a338-8e0aa720608a

STIX ID: report--3feec283-60ca-4f11-a338-8e0aa720608a

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2022-02-21

Last Modified Date: 2022-02-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft MSTIC details ACTINIUM (aka Gamaredon), an FSB‑attributed, long‑running cyber‑espionage campaign targeting Ukrainian government, military, NGOs, judiciary, law enforcement and related organizations; the group uses spear‑phishing with remote templates, staged VBS/PowerShell payloads, scheduled‑task persistence, and multiple malware families (PowerPunch, Pterodo, QuietSieve) to maintain access and exfiltrate sensitive data, and the report provides extensive IOCs (domains, IPs, SHA‑256s), observed wordlists, and detection/hunting queries for Microsoft security products.