logo

Gamaredon APT Targeting Ukraine with New Variants

ID: e4bc1885-8a38-50c8-87f1-a0f6d1f6e5bb

STIX ID: report--e4bc1885-8a38-50c8-87f1-a0f6d1f6e5bb

Feed Name: Cyble Blog

Threat Score
90/100

Date Published: 2025-05-09

Date Updated: 2026-07-16

...
...

**Executive Summary:** Cyble observed a renewed Gamaredon (Russia-linked APT) campaign targeting Ukrainian national security forces via spear-phishing documents that use template-injection to download payloads from attacker-controlled C2 servers; the report provides IoCs (hashes, domains, IP), describes the infection flow and TTPs, and notes limited endpoint detections indicating stealthy operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.