logo

Russian APT 'Gamaredon' Hits Ukraine With Fierce Phishing

ID: c89afced-e20c-5649-8cba-40b40129f1f8

STIX ID: report--c89afced-e20c-5649-8cba-40b40129f1f8

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-07-02

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Gamaredon (Russia-aligned APT) has resumed focused espionage against Ukrainian government entities using spear-phishing, weaponized USB/network drives, and a refreshed toolset. ESET observed increased sophistication including Cloudflare subdomain/tunnel abuse for C2 obfuscation, HTML smuggling via XHTML attachments, HTA/LNK/VBScript/PowerShell loaders, and multiple new tools (PteroGraphin, PteroPSDoor, PteroDespair, PteroTickle, PteroQuark, PteroStew, PteroBox) used for persistence, lateral movement and exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.