{"id":1499,"date":"2026-06-29T13:07:30","date_gmt":"2026-06-29T13:07:30","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1499"},"modified":"2026-06-29T13:07:30","modified_gmt":"2026-06-29T13:07:30","slug":"gamaredon-expands-ukraine-attacks-with-new-malware-and-cloud-service-abuse","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1499","title":{"rendered":"Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 29, 2026<\/span><\/span><span class=\"p-tags\">Cloud Security \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEijvTMs5lEwRQ2ndqc7YNsz1eNQK0XuR_q4uSjl8tLZ8Nh8vA4WRKZsQhyphenhyphenUx1O0gR-QJtdvAj8LDEUaGscAEXAlA9_e9c0LNtEeV-6NJzdqEdGt0gb7mDEUBNmlMNI2L05YQ8lPXA6kNBFL4s7BsjiJSPD72fyhQq2fmYJwZBPQhyHI4PN_zvSrnxtRbRtI\/s1700-e365\/uk.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025.<\/p>\n<p>Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half of the year. Primary targets of these efforts include Ukrainian governmental and military institutions.<\/p>\n<p>\u00abThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine,\u00bb ESET <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances\/\">said<\/a>. \u00abThe group&#8217;s ultimate goal continues to be the exfiltration of sensitive information and other critical data that could be exploited to support Russian interests in the ongoing war in Ukraine.\u00bb<\/p>\n<p>The spear-phishing campaigns make use of archive attachments or XHTML files that employ HTML smuggling to deliver malicious HTA downloaders that are responsible for dropping additional payloads, such as PteroSand. Some of the attacks have also weaponized a now-patched flaw in WinRAR (CVE-2025-8088) as a way of placing the malicious HTA downloader into the victim&#8217;s Windows Startup folder.<\/p>\n<p>This, in turn, causes the downloader to be automatically executed on the next login, thereby adding a persistence mechanism to the compromise chain. Gamaredon&#8217;s attacks are known to rely on weaponizers like PteroLNK and PteroPaste to facilitate lateral movement by infecting USB drives and network drives with malicious LNK files that, when opened by an unsuspecting user, trigger the retrieval of downloader malware.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Also used is PteroSetup, an older Visual Basic Script (VBScript) weaponizer first detected in January 2021 and likely assumed to be discontinued. The tool scans USB and mapped network drives for legitimate installer files, and if found, replaces them with 7z self-extracting (SFX) archives containing the original installer and a malicious VBScript downloader.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abIn 2025, the group&#8217;s reliance on third-party services grew significantly, with tunnel services and serverless worker platforms becoming an increasingly important part of how it hid its real back-end infrastructure,\u00bb ESET said.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhM2RC19XX7jG85kx8qEFZFEFHI5wEpntnb4zrbTi28D79XBGqwkesfBgQW39BKo5iGPvRjzeSPp8nqY2GtZS3HDD_4zENMDmkjEhfLHWgMQCup2OVLNh3nuWcYt1xSDjQk4msdx7mgJJl6cwGv8Kv9m2X5KxfnFZDYtZW1iAw5ptcsY3k1ooQjAQbZtGZe\/s1700-e365\/rar.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhM2RC19XX7jG85kx8qEFZFEFHI5wEpntnb4zrbTi28D79XBGqwkesfBgQW39BKo5iGPvRjzeSPp8nqY2GtZS3HDD_4zENMDmkjEhfLHWgMQCup2OVLNh3nuWcYt1xSDjQk4msdx7mgJJl6cwGv8Kv9m2X5KxfnFZDYtZW1iAw5ptcsY3k1ooQjAQbZtGZe\/s1700-e365\/rar.jpg\" alt=\"\" border=\"0\" data-original-height=\"481\" data-original-width=\"972\"\/><\/a><\/div>\n<p>The attacks are also characterized by the introduction of six new malicious PowerShell tools, broadening its custom malware arsenal &#8211;<\/p>\n<ul>\n<li><b>PteroDee<\/b> and <b>PteroCache<\/b> for fetching and executing PowerShell payloads in memory<\/li>\n<li><b>PteroDum<\/b> for fetching and executing VBScript payloads in memory<\/li>\n<li><b>PteroOdd<\/b> for fetching a single PowerShell payload using the Telegra.ph API and likely used in campaigns in which the Gamaredon actors collaborated with Turla<\/li>\n<li><b>PteroEffigy<\/b> for fetching the command-and-control (C2) server using the GoFile cloud storage service<\/li>\n<li><b>PteroPaste<\/b>, for weaponizing USB drives and downloading additional PowerShell payloads via an encrypted channel<\/li>\n<\/ul>\n<p>\u201cWhile the group took a short operational break in January 2025, Gamaredon spent much of its effort in the first half of that year developing and deploying new tools,\u00bb ESET researcher Zolt\u00e1n Rusn\u00e1k said.<\/p>\n<p>\u00abMany updates were made in the lead-up to major holidays in Russia and Crimea. Notably, no updates were observed during or immediately after these holidays, further suggesting that Gamaredon operators are probably government-affiliated employees.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Another noteworthy aspect of the threat actor&#8217;s campaign revolves around the use of a wide range of legitimate services as data exfiltration channels and dead drop resolvers to obtain details of the C2 server and to point malware to infrastructure already hidden behind tunnels or serverless workers. These include &#8211;<\/p>\n<ul>\n<li>Telegra.ph<\/li>\n<li>Teletype<\/li>\n<li>Rentry.co<\/li>\n<li>Write.as<\/li>\n<li>Dropbox<\/li>\n<li>GoFile<\/li>\n<li>DEV Community (dev.to)<\/li>\n<li>Mastodon<\/li>\n<li>Lesma<\/li>\n<li>Nopaste.net<\/li>\n<li>Paste.ee<\/li>\n<li>Wasabi<\/li>\n<li>Tebi<\/li>\n<li>Intercolo<\/li>\n<li>Dropbox<\/li>\n<\/ul>\n<p>\u00abAs in previous years, the group compensated for the relative simplicity of its malware with persistence, frequent updates, and an increasingly creative abuse of legitimate online services,\u00bb ESET said. \u00abGamaredon further expanded its use of dead drops, tunnels, workers, dynamic DNS, and cloud storage, making its operations more flexible and harder to disrupt.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 29, 2026Cloud Security \/ Malware A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1500,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[383,24,329,206,1870,42,572,451],"class_list":["post-1499","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abuse","tag-attacks","tag-cloud","tag-expands","tag-gamaredon","tag-malware","tag-service","tag-ukraine"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1499","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1499"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1499\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1500"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1499"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1499"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}