Threat intelligence
- Suspected origin
- Russia
- Targeted countries
- Russia
- TLP
- WHITE
(Lookingglass) The Lookingglass Cyber Threat Intelligence Group (CTIG) has been tracking an ongoing cyber espionage campaign named “Operation Armageddon”. The name was derived from multiple Microsoft Word documents used in the attacks. “Armagedon” (spelled incorrectly) was found in the “Last Saved By” and “Author” fields in multiple Microsoft Word documents. Although continuously developed, the campaign has been intermittently active at a small scale, and uses unsophisticated techniques. The attack timing suggests the campaign initially started due to Ukraine’s decision to accept the Ukraine-‐European Union Association Agreement (AA). The agreement was designed to improve economic integrations between Ukraine and the European Union. Russian leaders publicly stated that they believed this move by Ukraine directly threatened Russia’s national security. Although initial steps to join the Association occurred in March 2012, the campaign didn’t start until much later (mid‐2013), as Ukraine and the EU started to more actively move towards the agreement.
Russian actors began preparing for attacks in case Ukraine finalized the AA. The earliest identified modification timestamp of malware used in this campaign is June 26, 2013. A group of files with modification timestamps between August 12 and September 16, 2013 were used in the first wave of spear-phishing attacks, targeting government officials prior to the 10th Yalta Annual Meeting: “Changing Ukraine in a Changing World: Factors of Success.”
Also known as
ActiniumAqua BlizzardArmageddonBlue OtsoBlueAlphaCallistoDEV-0157G0047Gamaredon GroupIron TildenNastyShrewPrimitive BearSectorC08ShuckwormTrident UrsaUAC-0010UNC530Winterflounder
Tooling and malware
PowerPunchPteranodonQuietSievePingRegRemcos
MITRE ATT&CK techniques
T1005 Data from Local SystemT1025 Data from Removable MediaT1039 Data from Network Shared DriveT1113 Screen CaptureT1119 Automated CollectionT1001 Data ObfuscationT1090 ProxyT1095 Non-Application Layer ProtocolT1102 Web ServiceT1105 Ingress Tool TransferT1568 Dynamic ResolutionT1571 Non-Standard PortT1112 Modify RegistryT1685 Disable or Modify ToolsT1012 Query RegistryT1033 System Owner/User DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1120 Peripheral Device DiscoveryT1047 Windows Management InstrumentationT1106 Native APIT1020 Automated ExfiltrationT1041 Exfiltration Over C2 ChannelT1080 Taint Shared ContentT1091 Replication Through Removable MediaT1534 Internal SpearphishingT1137 Office Application StartupT1027 Obfuscated Files or InformationT1055 Process InjectionT1140 Deobfuscate/Decode Files or InformationT1221 Template InjectionT1480 Execution GuardrailsT1620 Reflective Code Loading
Coverage 4
threat-intel
The Gamaredon APT group continued its aggressive cyberattacks against Ukraine throughout 2025, utilizing a range of new malware and exploiting vulnerabilities to steal sensitive information. The group expanded its tactic…

threat-intel
The Russian cyber espionage group Gamaredon (also known as Aqua Blizzard) has significantly upgraded its arsenal and tactics, becoming a more effective threat actor, particularly in support of the war in Ukraine. The gro…

threat-intel
In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin…
threat-intel
The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc…
