Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services.…
Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services.…
PteroSand is a malware payload delivered by Gamaredon via HTA downloaders in spear-phishing campaigns targeting Ukraine.
PteroLNK is a weaponizer used by Gamaredon to infect USB and network drives with malicious LNK files for lateral movement.
PteroPaste is used by Gamaredon to weaponize USB drives and download additional PowerShell payloads via an encrypted channel.
PteroSetup is an older VBScript weaponizer used by Gamaredon to replace legitimate installer files with 7z SFX archives containing malicious VBScript downloaders.
PteroDee is a PowerShell tool used by Gamaredon to fetch and execute PowerShell payloads in memory.
PteroCache is a PowerShell tool used by Gamaredon to fetch and execute PowerShell payloads in memory.
PteroDum is a tool used by Gamaredon to fetch and execute VBScript payloads in memory.
PteroOdd is a PowerShell tool used by Gamaredon to fetch a single PowerShell payload using the Telegra.ph API, likely in collaboration with…
PteroEffigy is a tool used by Gamaredon to fetch the command-and-control server using the GoFile cloud storage service.