Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
ID: 2b7f06c2-5507-5a74-b9cc-53e7e7a7d3c2
STIX ID: report--2b7f06c2-5507-5a74-b9cc-53e7e7a7d3c2
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET documents that Gamaredon remained highly active in 2025, focusing exclusively on Ukrainian government and military targets: the group ran at least 35 spearphishing campaigns, introduced six new PowerShell tools and a revived VBScript weaponizer, adopted CVE-2025-8088 for persistence, and increasingly used tunnels, serverless workers, dynamic DNS, and legitimate third-party services as dead drops while exfiltrating stolen files to S3-compatible cloud storage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
