Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Cyberespionage has remained a constant feature of Russia’s war against Ukraine. ESET Research has long tracked Gamaredon, one of the most active Russia-aligned advanced persistent threat (APT) groups targeting Ukraine. The group, attributed by the Security Service of Ukraine (SSU) to the 18th Center of Information Security of Russia’s FSB, maintained a high operational tempo throughout 2025.
In our latest research, we analyze Gamaredon’s activity during 2025, including new tools added to its arsenal, significant shifts in how it protects its network infrastructure, and its growing use of legitimate third-party services to hide both command and control (C&C) information and stolen data. The full technical details are available in our latest white paper.
Key points of this blogpost:Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.We observed 35 distinct spearphishing campaigns against new targets. The majority of the campaigns were carried out in the...
Copyright of this story solely belongs to welivesecurity.com. To see the full text click HERE