Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
ID: 07d32519-ad6a-5bb1-a5c9-c0a4a43f1276
STIX ID: report--07d32519-ad6a-5bb1-a5c9-c0a4a43f1276
Feed Name: The Hacker News
Threat Score
**Executive summary:** Gamaredon ran at least 35 spear‑phishing campaigns in 2025 against Ukrainian government and military targets, using HTML smuggling and archive/XHTML attachments to deliver HTA downloaders and a growing Ptero* malware family (PowerShell and VBScript loaders), weaponized a patched WinRAR flaw for persistence, and increasingly leveraged legitimate cloud/tunnel services as dead drops and C2 channels to exfiltrate sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
