FSB-Linked Gamaredon Group Deployed Six New Malware Tools and 35 Spear-Phishing Campaigns Against Ukrainian Government Using Cloud Services as Command Channels
ESET Research documented 35 Gamaredon spear-phishing campaigns against Ukrainian governmental and military institutions in 2025, with tempo and scale increasing sharply through the second half
The Turla-Gamaredon tooling handoff, drawn from a single ESET investigation, signals FSB-aligned units consolidating operational infrastructure rather than running parallel campaigns, concentrating collection priority against Ukrainian institutions. Replacing direct C2 IP publication with dead drops on Telegram, Dropbox, and Mastodon that resolve through Cloudflare workers and devtunnels removes the most actionable network indicator defenders relied on. Sinkholing is no longer a viable primary response. Rotating exfiltration across sequential S3-compatible providers extends the compromise-to-recovery window across multiple cloud jurisdictions. The CVE-2025-8088 persistence chain, confirmed systematic across all 35 campaigns, ensures re-infection at login without renewed user interaction. The tool-sharing may instead reflect ad hoc instrument lending rather than unified FSB collection direction.
4 sources
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances -
WeLiveSecurity (ESET Research) - Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse -
The Hacker News - Russia's Gamaredon Adapts Tactics to Target Ukraine -
GovInfoSecurity - ESET Research: Russia's Gamaredon APT group unleashed spearphishing campaigns against Ukraine with an evolved toolset