Gamaredon_Group__2022__Microsoft_ACTINIUM-Ukrainian-organizations_02-04-2022.pdf
ID: 3feec283-60ca-4f11-a338-8e0aa720608a
STIX ID: report--3feec283-60ca-4f11-a338-8e0aa720608a
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2022-02-21
Last Modified Date: 2022-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft MSTIC details ACTINIUM (aka Gamaredon), an FSB‑attributed, long‑running cyber‑espionage campaign targeting Ukrainian government, military, NGOs, judiciary, law enforcement and related organizations; the group uses spear‑phishing with remote templates, staged VBS/PowerShell payloads, scheduled‑task persistence, and multiple malware families (PowerPunch, Pterodo, QuietSieve) to maintain access and exfiltrate sensitive data, and the report provides extensive IOCs (domains, IPs, SHA‑256s), observed wordlists, and detection/hunting queries for Microsoft security products.
