Intel Name: Russia’s trident ursa (aka gamaredon apt) cyber conflict operations unwavering since invasion of ukraine
Date of Scan: April 9, 2025
Impact: High
Summary: Since our previous update in early February on the advanced persistent threat (APT) group Trident Ursa (also known as Gamaredon, UAC-0010, Primitive Bear, Shuckworm), Ukraine has continued to face escalating cyber threats from Russia. The Security Service of Ukraine attributes Trident Ursa to Russia’s Federal Security Service (FSB). Throughout the ongoing conflict, the group has acted as a persistent access facilitator and intelligence collector. Trident Ursa remains one of the most active, aggressive, and persistent APTs focused on targeting Ukraine.