Gamaredon Group Intensifies Cyberespionage Against Ukraine in 2025

Gamaredon Group Intensifies Cyberespionage Against Ukraine in 2025

First seen 25 Jun 2026, 15:39 UTC Markets.Businessinsiderwww.globenewswire.com 88% similarity 74.4
Share:

Article Content

Browse articles
ThreatCluster

ESET Research has released findings on the Gamaredon group, a Russia-aligned APT, detailing its cyberespionage activities throughout 2025. The group focused on exfiltrating sensitive data from Ukrainian governmental and military institutions, employing new tools and tactics. Notably, Gamaredon introduced six new PowerShell tools, including PteroPaste, which enhances its capabilities for lateral movement and data exfiltration. The group remained active despite a brief operational pause in January 2025, with increased spear phishing campaigns in the latter half of the year. Collaboration with other Russia-aligned threat actors, such as Turla and UAC-0099, indicates a coordinated effort to amplify their impact. The research highlights the use of legitimate third-party services to obscure command and control operations and data theft. Gamaredon's activities align closely with Russian geopolitical objectives amid the ongoing conflict with Ukraine.

Key Points: • Gamaredon introduced six new PowerShell tools in 2025, enhancing its cyber capabilities. • The group focused on spear phishing campaigns, significantly increasing their frequency and scale. • Collaboration with other Russia-aligned groups indicates a coordinated cyberespionage strategy.

ThreatCluster AI

Timeline

2025-01-05
Gamaredon takes operational break
The group paused its activities for a short period in January 2025, likely to regroup and refine its tactics.
www.globenewswire.com
2025-06-25
ESET Research publishes Gamaredon report
ESET details Gamaredon's activities, tools, and collaborations in a comprehensive report.
Markets.Businessinsider
2025-08-08
CVE-2025-8088 published
A critical vulnerability was published, with active exploitation reported shortly after.
N/A
2025-08-12
CVE-2025-8088 added to CISA KEV
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.
N/A
Recent
Increased spear phishing campaigns observed
Gamaredon ramped up its spear phishing efforts in the latter half of 2025, targeting Ukrainian entities.
Markets.Businessinsider

Community

Browse all →