Gamaredon APT Expands Ukraine Attacks With New Malware Arsenal
The Russian advanced persistent threat group Gamaredon maintained an aggressive focus on Ukrainian governmental and military institutions throughout 2025, mounting 35 distinct spear-phishing campaigns according to Slovakian cybersecurity firm ESET. Most activity was concentrated in the second half of the year, following a brief operational pause in January. The group's stated objective remains the exfiltration of sensitive intelligence that could support Russian strategic interests in the ongoing war.
Gamaredon's campaigns relied heavily on archive attachments and XHTML files leveraging HTML smuggling to deliver malicious HTA downloaders, including a newly observed payload dubbed PteroSand. Attackers also weaponized a now-patched WinRAR path-traversal flaw (CVE-2025-8088) to plant HTA downloaders inside the Windows Startup folder, guaranteeing automatic execution on the next user login and establishing persistence. Lateral movement was facilitated by the group's signature weaponizers PteroLNK and PteroPaste, which infected USB and mapped network drives with malicious LNK shortcuts, alongside the older VBScript tool PteroSetup that replaced legitimate installers with 7z self-extracting archives containing trojanized payloads.
A notable shift in 2025 was Gamaredon's expanded reliance on legitimate cloud and tunnel services to obscure its command-and-control backbone. Researchers identified six new PowerShell tools added to its arsenal: PteroDee and PteroCache for in-memory payload execution, PteroDum for VBScript loading, PteroOdd for retrieving payloads via the Telegra.ph API in apparent collaboration with the Turla APT group, PteroEffigy for C2 retrieval through the GoFile cloud storage platform, and a revamped PteroPaste for weaponizing removable media with encrypted download channels. This pivot toward serverless worker platforms and consumer-grade file-sharing services makes traditional IP-based detection increasingly difficult, making infrastructure analysis tools such as a WHOIS lookup and an SSL/TLS checker essential for defenders tracking the group's evolving footprint. Organizations concerned about outbound traffic tunneling through anonymizing infrastructure should also run a DNS leak test to verify whether internal DNS queries are being exposed through unauthorized proxies or resolvers.