2019-04
The discovered attack appears to be designed to lure military personnel: it leverages a legit document of the “State of the Armed Forces of Ukraine” dated back in the 2nd April 2019.
https://blog.yoroi.company/research/the-russian-shadow-in-eastern-europe-ukrainian-mod-campaign/
2019-05
The Gamaredon attacks against Ukraine doesn’t seem to have stopped. After a month since our last report we spotted a new suspicious email potentially linked to the Gamaredon group.
https://blog.yoroi.company/research/the-russian-shadow-in-eastern-europe-a-month-later/
2019-07
EvilGnome: Rare Malware Spying on Linux Desktop Users
https://www.intezer.com/blog-evilgnome-rare-malware-spying-on-linux-desktop-users/
2019-10
Lure documents observed appear to target Ukrainian entities such as diplomats, government employees, military officials, and more.
https://www.anomali.com/blog/malicious-activity-aligning-with-gamaredon-ttps-targets-ukraine#When:15:00:00Z
2019-11
New wave of attacks
https://labs.sentinelone.com/pro-russian-cyberspy-gamaredon-intensifies-ukrainian-security-targeting/
2019-12
Gamaredon APT Improves Toolset to Target Ukraine Government, Military
https://threatpost.com/gamaredon-apt-toolset-ukraine/152568/
2020-03
Moving into March 2020, countries worldwide are still struggling to manage the spread of the viral disease now known as COVID-19. In cyberspace, threat actors are using the topic of COVID-19 to their advantage with numerous examples of malicious activity using COVID-19 as lure documents in phishing campaigns.
https://info.ai.baesystems.com/rs/308-OXI-896/images/COVID-19-Infographic-Mar2020.pdf
2020 Early
Since the beginning of 2020 there are reports that APT group has taken advantage of the coronavirus pandemic and used it as a lure to attract victims to open malicious attachments sent with spearphishing emails.
https://www.ria.ee/sites/default/files/content-editors/kuberturve/tale_of_gamaredon_infection.pdf
2020-04
The attacks we found all arrived through targeted emails (MITRE ATT&CK framework ID T1193). One of them even had the subject “Coronavirus (2019-nCoV).”
https://blog.trendmicro.com/trendlabs-security-intelligence/gamaredon-apt-group-use-covid-19-lure-in-campaigns/
2021-01
Russia-Sponsored Group Employs Apparently Legitimate Documents Aligned to Growing Hostilities Between Russia and Ukraine
https://www.anomali.com/blog/primitive-bear-gamaredon-targets-ukraine-with-timely-themes
2021-07
Shuckworm Continues Cyber-Espionage Attacks Against Ukraine
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-gamaredon-espionage-ukraine
2021-10
Since October 2021, ACTINIUM has targeted or compromised accounts at organizations critical to emergency response and ensuring the security of Ukrainian territory, as well as organizations that would be involved in coordinating the distribution of international and humanitarian aid to Ukraine in a crisis.
https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/
2021-12
Lookout Discovers Two Russian Android Spyware Families from Gamaredon APT
https://www.lookout.com/threat-intelligence/article/gamaredon-russian-android-surveillanceware
2022-01
Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine
https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/
2022-02
Gamaredon APT utilised new malware payloads to target Ukraine
https://www.izoologic.com/2022/02/23/gamaredon-apt-utilised-new-malware-payloads-to-target-ukraine/
2022-02
Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine
https://unit42.paloaltonetworks.com/trident-ursa/
2022-03
Network Footprints of Gamaredon Group
https://blogs.cisco.com/security/network-footprints-of-gamaredon-group
2022-04
Ukraine spots Russian-linked 'Armageddon' phishing attacks
https://www.bleepingcomputer.com/news/security/ukraine-spots-russian-linked-armageddon-phishing-attacks/
2022-04
Shuckworm: Espionage Group Continues Intense Campaign Against Ukraine
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-intense-campaign-ukraine
2022-05
Ukraine CERT-UA warns of new attacks launched by Russia-linked Armageddon APT
https://securityaffairs.co/wordpress/131296/breaking-news/cert-ua-warns-armageddon-apt.html
2022-07
Shuckworm: Russia-Linked Group Maintains Ukraine Focus
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/russia-ukraine-shuckworm
2022-09
Gamaredon APT targets Ukrainian government agencies in new campaign
https://blog.talosintelligence.com/gamaredon-apt-targets-ukrainian-agencies/
2022-11
Gamaredon (Ab)uses Telegram to Target Ukrainian Organizations
https://blogs.blackberry.com/en/2023/01/gamaredon-abuses-telegram-to-target-ukrainian-organizations
2022-11
Cyberattacks Targeting Ukraine Increase 20-fold at End of 2022 Fueled by Russia-linked Gamaredon Activity
https://www.trellix.com/en-us/about/newsroom/stories/research/cyberattacks-targeting-ukraine-increase.html
2023-01
Russia-backed hacker group Gamaredon attacking Ukraine with info-stealing malware
https://therecord.media/russia-backed-hacker-group-gamaredon-attacking-ukraine-with-info-stealing-malware/
2024-01
Operation “STEADY#URSA”
Securonix Threat Research Security Advisory: Analysis and Detection of STEADY#URSA Attack Campaign Targeting Ukraine Military Dropping New Covert SUBTLE-PAWS PowerShell Backdoor
https://www.securonix.com/blog/security-advisory-steadyursa-attack-campaign-targets-ukraine-military/
2024-09
BlueAlpha Abuses Cloudflare Tunneling Service for GammaDrop Staging Infrastructure
https://go.recordedfuture.com/hubfs/reports/cta-ru-2024-1205.pdf
2024-10
ESET Research: Russia’s Gamaredon APT group unleashed spearphishing campaigns against Ukraine with an evolved toolset
https://www.eset.com/us/about/newsroom/research/eset-research-russias-gamaredon-apt-group-unleashed-spearphishing-campaigns-against-ukraine-with-an-evolved-toolset/
2024-11
Gamaredon campaign abuses LNK files to distribute Remcos backdoor
https://blog.talosintelligence.com/gamaredon-campaign-distribute-remcos/
2025-02
Shuckworm Targets Foreign Military Mission Based in Ukraine
https://www.security.com/threat-intelligence/shuckworm-ukraine-gammasteel