Adversary Intelligence — 2026-06-29

FSB-Linked Gamaredon Group Deployed Six New Malware Tools and 35 Spear-Phishing Campaigns Against Ukrainian Government Using Cloud Services as Command Channels

BLUFConvergence of FSB cyber units onto shared cloud-native infrastructure strips Ukrainian defenders of the network-layer indicators that previously enabled rapid detection and disruption of Gamaredon operations.

ESET Research documented 35 Gamaredon spear-phishing campaigns against Ukrainian governmental and military institutions in 2025, with tempo and scale increasing sharply through the second half 12. The group introduced six PowerShell tools, led by PteroPaste, which combines downloader, USB weaponizer, and persistence functions and was also deployed by FSB-linked Turla in a documented 2025 collaboration 13. From September 26, operators exploited WinRAR vulnerability CVE-2025-8088 to plant HTA downloaders in victims' Startup folders 13. ESET reported the group shifted exfiltration to S3 cloud storage (moving from Wasabi to Tebi to Intercolo), staged command-and-control addresses on Telegram, Dropbox, and Mastodon as dead drops, and from May hid back-end servers behind Cloudflare workers and Microsoft devtunnels 123.

Analysis
The Turla-Gamaredon tooling handoff, drawn from a single ESET investigation, signals FSB-aligned units consolidating operational infrastructure rather than running parallel campaigns, concentrating collection priority against Ukrainian institutions. Replacing direct C2 IP publication with dead drops on Telegram, Dropbox, and Mastodon that resolve through Cloudflare workers and devtunnels removes the most actionable network indicator defenders relied on. Sinkholing is no longer a viable primary response. Rotating exfiltration across sequential S3-compatible providers extends the compromise-to-recovery window across multiple cloud jurisdictions. The CVE-2025-8088 persistence chain, confirmed systematic across all 35 campaigns, ensures re-infection at login without renewed user interaction. The tool-sharing may instead reflect ad hoc instrument lending rather than unified FSB collection direction.
4 sources
  1. Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances - WeLiveSecurity (ESET Research)
  2. Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse - The Hacker News
  3. Russia's Gamaredon Adapts Tactics to Target Ukraine - GovInfoSecurity
  4. ESET Research: Russia's Gamaredon APT group unleashed spearphishing campaigns against Ukraine with an evolved toolset

View in full brief →

UNCLASSIFIED // OPEN SOURCE