logo

Gamaredon_Group__2022__PaloAltoNetworks_Russias-Gamaredon-PrimitiveBear-Targeting-Ukraine_02-03-2022.pdf

ID: 85b475de-c139-449e-a805-362514b8ad22

STIX ID: report--85b475de-c139-449e-a805-362514b8ad22

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2022-02-21

Last Modified Date: 2022-02-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports that the Gamaredon (aka Primitive Bear) APT has been actively targeting Ukrainian government and related organizations with phishing and multi-stage malware campaigns; researchers mapped three infrastructure clusters (downloaders, a file stealer, and the Pteranodon RAT) linking ~700 domains, ~215 IPs and >100 malware samples, documented delivery via remote Word templates and SFX archives deploying UltraVNC and custom tools, and provided IoCs and mitigations to defend against ongoing operations.