logo

OldGremlin: A Stealthy Russian-Speaking Ransomware and Espionage Threat Group Evolving Into a Precision Striking APT

ID: 21e3e40f-22b3-5bd5-852b-46e7e5b0b716

STIX ID: report--21e3e40f-22b3-5bd5-852b-46e7e5b0b716

Feed Name: Brandefense Blog

Threat Score
85/100

Date Published: 2025-12-29

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

OldGremlin is a Russian-speaking, financially motivated hybrid threat actor active from 2020 through 2025 that combines APT-level reconnaissance and long dwell times with targeted ransomware double-extortion operations; the group uses spear-phishing in multiple languages, credential theft (RDP/VPN), custom backdoors (TinyNode, TinyShell), modular implants, multi-stage loaders, cloud-tunneled C2, and supply-chain impersonation to maximize impact across sectors including finance, logistics, manufacturing, retail and healthcare.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.