Gamaredon_Group__2022__PaloAltoNetworks_Russias-Gamaredon-PrimitiveBear-Targeting-Ukraine_02-03-2022.pdf
ID: 85b475de-c139-449e-a805-362514b8ad22
STIX ID: report--85b475de-c139-449e-a805-362514b8ad22
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2022-02-21
Last Modified Date: 2022-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports that the Gamaredon (aka Primitive Bear) APT has been actively targeting Ukrainian government and related organizations with phishing and multi-stage malware campaigns; researchers mapped three infrastructure clusters (downloaders, a file stealer, and the Pteranodon RAT) linking ~700 domains, ~215 IPs and >100 malware samples, documented delivery via remote Word templates and SFX archives deploying UltraVNC and custom tools, and provided IoCs and mitigations to defend against ongoing operations.
