RST TI Report Digest: 29 Jun 2026
ID: 18bef507-f228-5a5a-af43-e5cb148bc883
STIX ID: report--18bef507-f228-5a5a-af43-e5cb148bc883
Feed Name: RST Cloud Blog
**ESET Research: Gamaredon 2025 — Key findings:** ESET documents that Gamaredon continued focused cyber‑espionage against Ukrainian government and military targets in 2025, conducting 35 spearphishing campaigns and expanding its toolkit with multiple new PowerShell loaders and revived payloads (PteroPaste, PteroSetup). The group leveraged HTML smuggling, malicious attachments, exploited CVE-2025-8088 for persistence, and increasingly abused legitimate services (cloud platforms, tunnels, dynamic DNS) and dead‑drop techniques to hide C2 and exfiltrate data; the report includes extensive IoCs (many IPs, domains, and SHA1 hashes) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
