APT / THREAT GROUP

GCMAN

🇷🇺Russia-attributed
1
campaigns
2
aliases
Last seen:Mar 17, 2026

Intelligence Profile

[GCMAN](https://attack.mitre.org/groups/G0036) is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. (Citation: Securelist GCMAN)

Threat Analysis

GCMAN is a known-sophistication threat actor attributed to Russia, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

GCMAN — Active Operations March 2026

GCMAN is a unknown-motivation threat actor attributed to Russia. GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services....

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Origin🇷🇺 Russia
Aliases2
SourceMalpedia

Also Known As

G0036GCMAN

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.