Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Cybersecurity Classified by Officially
Cyberespionage has remained a constant feature of Russia’s war against Ukraine. ESET Research has long tracked Gamaredon, one of the most active Russia-aligned advanced persistent threat (APT) groups targeting Ukraine. The group, attributed by the Security Service of Ukraine (SSU) to the 18th Center of Information Security of Russia’s FSB, maintained a high operational tempo throughout 2025.
In our latest research, we analyze Gamaredon’s activity during 2025, including new tools added to its arsenal, significant shifts in how it protects its network infrastructure, and its growing use of legitimate third-party services to hide both command and control (C&C) information and stolen data. The full technical details are available in our latest white paper.
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
This is an extract. The publication continues at the source.
Read the original at the source: https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/
Officially imported this from ESET’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- ESET — imported from official source
- Official source
- https://www.welivesecurity.com/en/rss/feed/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 1 recorded
- Identity
https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-worke...