Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services. Slovakian cybersecurity company ESET observed 35 distinct spear-phishing campaigns targeting Ukrainian governmental and military institutions.
The attacks use archive attachments or XHTML files with HTML smuggling to deliver malicious HTA downloaders that drop payloads like PteroSand. Some campaigns weaponized a patched WinRAR flaw (CVE-2025-8088) to place downloaders in the Windows Startup folder for persistence. Gamaredon also uses weaponizers such as PteroLNK, PteroPaste, and PteroSetup for lateral movement via infected USB and network drives.
In 2025, the group introduced six new PowerShell tools: PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, and PteroPaste. These tools fetch and execute payloads in memory, use the Telegra.ph API, and leverage cloud storage services like GoFile for C2 communication. Gamaredon also abused services including Telegra.ph, Teletype, Rentry.co, Write.as, Dropbox, GoFile, DEV Community, Mastodon, Lesma, Nopaste.net, Paste.ee, Wasabi, Tebi, and Intercolo for data exfiltration and dead drop resolvers.
ESET noted that Gamaredon compensated for its malware’s simplicity with persistence, frequent updates, and creative abuse of legitimate services, making operations more flexible and harder to disrupt.
CVEs: CVE-2025-8088, CVE-2026-20245
Attack groups: Gamaredon, Turla
Malware: PteroSand, PteroLNK, PteroPaste, PteroSetup, PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy
Companies: ESET
Products: WinRAR
Service providers: Dropbox, GoFile, Telegra.ph, Teletype, Rentry.co, Write.as, DEV Community, Mastodon, Lesma, Nopaste.net, Paste.ee, Wasabi
Original source: thehackernews.com