CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

June 29, 2026

Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services. Slovakian cybersecurity company ESET observed 35 distinct spear-phishing campaigns targeting Ukrainian governmental and military institutions.

The attacks use archive attachments or XHTML files with HTML smuggling to deliver malicious HTA downloaders that drop payloads like PteroSand. Some campaigns weaponized a patched WinRAR flaw (CVE-2025-8088) to place downloaders in the Windows Startup folder for persistence. Gamaredon also uses weaponizers such as PteroLNK, PteroPaste, and PteroSetup for lateral movement via infected USB and network drives.

In 2025, the group introduced six new PowerShell tools: PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, and PteroPaste. These tools fetch and execute payloads in memory, use the Telegra.ph API, and leverage cloud storage services like GoFile for C2 communication. Gamaredon also abused services including Telegra.ph, Teletype, Rentry.co, Write.as, Dropbox, GoFile, DEV Community, Mastodon, Lesma, Nopaste.net, Paste.ee, Wasabi, Tebi, and Intercolo for data exfiltration and dead drop resolvers.

ESET noted that Gamaredon compensated for its malware’s simplicity with persistence, frequent updates, and creative abuse of legitimate services, making operations more flexible and harder to disrupt.

CVEs: CVE-2025-8088, CVE-2026-20245

Attack groups: Gamaredon, Turla

Malware: PteroSand, PteroLNK, PteroPaste, PteroSetup, PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy

Companies: ESET

Products: WinRAR

Service providers: Dropbox, GoFile, Telegra.ph, Teletype, Rentry.co, Write.as, DEV Community, Mastodon, Lesma, Nopaste.net, Paste.ee, Wasabi