Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Imported from official source

Cybersecurity Classified by Officially

Cyberespionage has remained a constant feature of Russia’s war against Ukraine. ESET Research has long tracked Gamaredon, one of the most active Russia-aligned advanced persistent threat (APT) groups targeting Ukraine. The group, attributed by the Security Service of Ukraine (SSU) to the 18th Center of Information Security of Russia’s FSB, maintained a high operational tempo throughout 2025.

In our latest research, we analyze Gamaredon’s activity during 2025, including new tools added to its arsenal, significant shifts in how it protects its network infrastructure, and its growing use of legitimate third-party services to hide both command and control (C&C) information and stolen data. The full technical details are available in our latest white paper.

  • Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.
  • We observed 35 distinct spearphishing campaigns against new targets. The majority of the campaigns were carried out in the second half of the year, and they were significantly larger than earlier ones.
  • Additional targets were compromised via multiple custom weaponizers designed for lateral movement.
  • Gamaredon operators developed and deployed six new malicious PowerShell tools, which we analyze in our white paper, and resurrected an old VBScript weaponizer – PteroSetup.
  • The file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo), which became the primary exfiltration method.
  • Gamaredon operators sought new ways to protect their network infrastructure, with their C&C servers now hidden behind various third-party services such as tunnels, workers, DDNS (dynamic DNS), and PaaS (platform as a service).
  • They also abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers and distributing payloads.
  • Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

    This is an extract. The publication continues at the source.

    Read the original at the source: https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/

    Officially imported this from ESET’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    ESET — imported from official source
    Official source
    https://www.welivesecurity.com/en/rss/feed/ RSS
    Imported
    September 18, 2026 11:35
    Versions
    1 recorded
    Identity
    https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-worke...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.