The Russian APT group Gamaredon isn’t slowing down. ESET tracked 35 distinct spear-phishing campaigns from the group targeting Ukrainian government and military institutions throughout 2025, with activity concentrated in the second half of the year.
Gamaredon’s playbook is well-established but constantly evolving. Attacks typically arrive via archive attachments or XHTML files using HTML smuggling to deliver malicious HTA downloaders. Those downloaders then drop additional payloads like PteroSand.
Some campaigns exploited a now-patched WinRAR vulnerability, CVE-2025-8088, to place the downloader in the Windows Startup folder for persistence. That’s a nice touch — using a known, patched flaw because you know not everyone patches promptly.
The group has also relied on PteroLNK and PteroPaste for lateral movement through infected USB and network drives, plus PteroSetup which replaces legitimate installer files with malicious 7z archives. Six new PowerShell tools — PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, and PteroPaste — expanded their custom malware arsenal.
What makes Gamaredon harder to track is their use of legitimate services. Telegra.ph, Dropbox, and GoFile all serve as data exfiltration and command-and-control channels. That’s a practical choice — blending malicious traffic with normal service traffic makes disruption harder.
The group’s goal remains straightforward: exfiltrate sensitive information to support Russian interests. And they’re clearly willing to keep iterating on their tooling to do it.
