Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatphishing-campaign-intelligencecommand-and-control-method

Gamaredon Expanded Ukraine Espionage With New PowerShell Tools and Cloud-Hidden C2

Updated 3h agoFirst seen Jun 25, 20265 sources

Russia-aligned Gamaredon significantly upgraded its cyberespionage operations against Ukrainian government and military organizations during 2025, according to ESET. The group ran 35 spear-phishing campaigns, introduced six new PowerShell-based tools, revived the VBScript weaponizer PteroSetup, and exploited CVE-2025-8088 in WinRAR to establish persistence through malicious HTA downloaders placed in Startup folders. ESET said Gamaredon also expanded lateral movement and USB-based propagation, with the newly documented PteroPaste able to copy a malicious downloader to connected USB drives while disguising it as a Word document shortcut.

The group increasingly concealed command-and-control and data theft behind legitimate services, using Cloudflare Workers, Microsoft dev tunnels, Loophole, DDNS providers, messaging and blogging platforms, paste sites, and cloud storage to mask malicious traffic and stage payloads. Newer malware variants retrieved encrypted C2 data from dead-drop locations such as Telegram, Dropbox, GoFile, and Mastodon, while upgraded stealers including PteroPSDoor and PteroVDoor exfiltrated stolen files to S3-compatible storage such as Wasabi, Tebi, and Intercolo. ESET also observed Gamaredon collaborating with Turla in early 2025, providing initial access that supported deployment of the Kazuar framework.

Share:
Gamaredon Expanded Ukraine Espionage With New PowerShell Tools and Cloud-Hidden C2
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Jun 26, 20264d ago

Gurucul published Gamaredon IOCs and detection queries

Gurucul's threat research report released a detailed IOC set for Gamaredon's 2025 activity, including domains, URLs, three IP addresses, and 22 SHA-1 hashes. The report also provided Gurucul TDIR detection queries to help identify related malicious activity.

Gamaredon in 2025: Leveraging Tunnels, Workers, Dead Drops, and New Alliances | Community Portal | Gurucul
Jun 25, 20265d ago

Intercolo became Gamaredon's primary exfiltration destination by December 2025

By December 2025, Intercolo had become the primary S3-compatible destination for Gamaredon's stolen-data exfiltration. This marked the latest observed shift in the group's cloud-based exfiltration infrastructure.

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Gamaredon upgraded stealers to exfiltrate data to S3-compatible storage

During 2025, Gamaredon updated malware including PteroPSDoor and PteroVDoor to exfiltrate stolen files to S3-compatible cloud storage providers. Reported destinations shifted from Wasabi to Tebi and later to Intercolo as the group blended malicious traffic with legitimate cloud usage.

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

Gamaredon shifted to larger spear-phishing activity in second half of 2025

In the second half of 2025, Gamaredon escalated its operations with at least 35 spear-phishing campaigns. Reporting says these upgrades enabled larger attacks focused exclusively on Ukrainian governmental and military institutions.

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

Gamaredon documented new PteroPaste USB-capable malware

ESET documented PteroPaste as a new and more complex Gamaredon tool that combines downloader, USB weaponization, and runner functions. It can copy a malicious downloader to connected USB drives disguised as a Word document shortcut and use Dropbox in its workflow.

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

Gamaredon increased abuse of legitimate services for C2 concealment

A major trend during 2025 was Gamaredon's expanded use of legitimate third-party services to hide command-and-control infrastructure and stage payloads. Reported services included Cloudflare Workers, Microsoft dev tunnels, Loophole, DDNS, messaging platforms, blogging sites, paste services, and cloud storage.

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

Gamaredon began exploiting CVE-2025-8088 in WinRAR

In 2025, Gamaredon started exploiting CVE-2025-8088 in WinRAR to gain persistence, including use of malicious HTA downloaders placed in Startup folders. The vulnerability became part of the group's infection and persistence chain.

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Gamaredon revived PteroSetup and expanded lateral movement in 2025

In 2025, Gamaredon revived its older VBScript weaponizer PteroSetup and expanded lateral-movement capabilities with multiple weaponizers. These changes formed part of a broader refresh of the group's tooling.

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Gamaredon introduced six new PowerShell tools in first half of 2025

During the first half of 2025, Gamaredon developed six new PowerShell-based tools and expanded its malware toolkit. The additions supported the group's continued cyberespionage operations against Ukrainian government and military targets.

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

Gamaredon collaborated with Turla in early 2025

ESET observed Gamaredon working with the Russian APT Turla in early 2025, with reporting indicating Gamaredon provided initial access to support deployment of Turla's Kazuar framework. This was cited as evidence of coordination among Russia-aligned threat actors.

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

51 LINKEDOpen in app
Affected products
4 linked
WinrarTelegramAmazon Simple Storage ServiceDropbox
Organizations
27 linked
WinRARClever-CloudAmazon Web ServicesColorTokensEsetCloudflareDropboxDark ReadingSupabaseOutpost24Microsoft CorporationTelegramWasabi TechnologiesDEV CommunityNo-IpPaste.eeTelegra.phMastodonRentryGoFileTebiGuruculTeletypeLoophole LabsIntercoloWrite.asRentry Co
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Gamaredon Expanded Ukraine Espionage With New PowerShell Tools and Cloud-Hidden C2 | Mallory