Vexday analysis
Gamaredon Group é um grupo suspeito de espionagem cibernética de origem russa que atua contra organizações militares, de segurança pública, do judiciário, sem fins lucrativos e não governamentais na Ucrânia desde pelo menos 2013. Em novembro de 2021, o governo ucraniano atribuiu publicamente o grupo ao Centro 18 do Serviço Federal de Segurança da Rússia (FSB), avaliação posteriormente corroborada por múltiplos pesquisadores independentes de segurança. Registrado no MITRE ATT&CK como G0047, o grupo é rastreado sob os aliases IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon, Shuckworm e DEV-0157, com 70 técnicas documentadas na base de conhecimento.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 70
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Known infrastructure 466
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
103.83.87.87:26900Remcosthreatfox103.83.87.87:22300Remcosthreatfox103.83.87.87:27900Remcosthreatfox103.83.87.87:24900Remcosthreatfoxwhichkindwahalabethisonesooluwahelurboi.duckdns.orgRemcosthreatfox155.103.69.20:14647Remcosthreatfoxeventras.duckdns.orgRemcosthreatfox107.175.88.92:2404Remcosthreatfox87.120.244.219:13131Remcosthreatfox77.110.108.14:9001Remcosthreatfox80.97.160.237:23401Remcosthreatfox91.193.7.162:13309Remcosthreatfox185.91.126.112:443Remcosthreatfox45.74.3.160:2404Remcosthreatfox144.24.14.113:7005Remcosthreatfox104.251.181.148:1427Remcosthreatfox185.116.238.123:8088Remcosthreatfox15.204.115.143:2404Remcosthreatfox104.251.181.148:443Remcosthreatfox104.251.181.148:80Remcosthreatfox185.91.126.107:443Remcosthreatfoxxoso6640.comRemcosthreatfoxaseguradora2026.kozow.comRemcosthreatfox2301amarilloa.kozow.comRemcosthreatfoxnordking.spaceRemcosthreatfoxnordkingbackup.spaceRemcosthreatfoxcreatifanay.duckdns.orgRemcosthreatfoxcrushanytics.duckdns.orgRemcosthreatfoxnordkingbackup1.spaceRemcosthreatfoxnordkingbackup2.spaceRemcosthreatfox+466 indicators in total. See them all on the IOCs page.
References
Gamaredon Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →