Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionageinitial-access-methodthreat-infrastructure-trackingcommand-and-control-method

Gamaredon Ran Large-Scale Espionage Campaigns Using Crimeware-Style Delivery

Updated 15h agoFirst seen May 25, 20261 source

Cisco Talos reported that the Gamaredon threat group conducted at least four campaigns from 2020 onward, combining nation-state espionage objectives with high-volume, crimeware-like delivery methods. The operations used template injection, trojanized installers, self-extracting archives, spam, and scripts including VBS, VBA, and batch files to gain initial access and profile victims before selectively deploying second-stage payloads. Talos said the group operated more than 600 first-stage C2 domains and over 330 IP addresses across 16 countries, with infrastructure heavily concentrated in Russia.

The campaigns showed a strong focus on Ukrainian targets, including Russian-language lures themed around Ukrainian government entities, while also reaching organizations outside Ukraine such as a major African bank, U.S. educational institutions, and European telecommunications and hosting providers. Talos highlighted examples including a trojanized Zoom installer, an unusually large 68 MB VBS file likely designed to evade sandbox analysis, and a long-running operation that excluded more than 1,700 IP addresses in 43 countries from infection. Researchers assessed Gamaredon as a prolific, noisy, likely second-tier APT focused on espionage and information collection rather than direct monetization.

Share:
Gamaredon Ran Large-Scale Espionage Campaigns Using Crimeware-Style Delivery
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 23, 20215y ago

Talos publishes comprehensive report on Gamaredon activity

Cisco Talos published a report summarizing its findings on Gamaredon, including selective second-stage payload delivery based on reconnaissance and a campaign that excluded more than 1,700 IP addresses in 43 countries from infection. The report assessed Gamaredon as a likely second-tier APT focused on espionage and information collection rather than direct monetization.

Gamaredon infrastructure and targeting details are documented

Talos reported that Gamaredon operated more than 600 first-stage C2 domains and over 330 IP addresses across 16 countries, with infrastructure heavily concentrated in Russia. The campaigns showed strong interest in Ukrainian targets while also affecting a major African bank, U.S. educational institutions, and European telecommunications and hosting providers.

Talos observes four Gamaredon campaigns active from 2020 onward

Cisco Talos analyzed four Gamaredon campaigns that were active from 2020 onward, describing the group as a noisy, prolific APT using crimeware-like tactics at scale. Observed techniques included template injection, trojanized installers, self-extracting archives, spam, VBS, VBA, and batch scripts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Threat actors
2 linked
Affected products
7 linked
ZoomAdvanced Malware ProtectionUmbrellaMeraki MxWeb Security ApplianceSnortOpera
Organizations
4 linked
Cisco SystemsDigitaloceanZoom CommunicationsSnort.org
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.