INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Abuse

| 2026-06-29 11:40 CRITICAL HIGH
Executive Summary AI-generated
The Russian advanced persistent threat (APT) group, Gamaredon, has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine. The group's ultimate goal remains the exfiltration of sensitive information and other critical data that could be exploited to support Russian interests in the war-torn country. Gamaredon's tactics have been refined over time, with notable updates made in the lead-up to major holidays in Russia and Crimea. Notably, no updates were observed during or immediately after these holidays, suggesting that Gamaredon operators are probably government-affiliated employees. The group has also continued to adapt its methods, including the use of spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half of the year. These campaigns employ archive attachments or XHTML files that employ HTML smuggling to deliver malicious HTA downloaders, which are responsible for dropping additional payloads. Gamaredon's attacks have been known to rely on weaponizers like PteroLNK and PteroPaste to facilitate lateral movement by infecting USB drives and network drives with malicious LNK files. The group has also used a wide range of legitimate services as data exfiltration channels and dead drop resolvers, obtaining details of the C2 server and pointing malware to infrastructure already hidden behind tunnels or serverless workers. Furthermore, Gamaredon's attacks have weaponized a now-patched flaw in WinRAR (CVE-2025-8088) as a way of placing the malicious HTA downloader into the victim's Windows Startup folder. This highlights the group's continued exploitation of known vulnerabilities and its ability to adapt to new security measures. The primary targets of these efforts include Ukrainian governmental and military institutions, with Gamaredon also targeting other organizations in the region. The group's tactics have been refined over time, demonstrating a high degree of sophistication and adaptability. As the threat continues to evolve, it is essential for defenders to remain vigilant and proactive in their defense strategies. This includes staying informed about the latest threats and tactics employed by Gamaredon, as well as implementing robust security measures to protect against these types of attacks.
Technical Mitigations AI-generated
* Use a reputable antivirus software and keep it up to date to protect against malware like the one used by Gamaredon. * Be cautious when opening archive attachments or XHTML files, as they may contain malicious payloads that can compromise your system's security. * Regularly scan your devices for signs of malware and update your operating system and applications promptly to prevent exploitation of known vulnerabilities. * Use strong passwords and enable multi-factor authentication whenever possible to add an extra layer of protection against unauthorized access. * Be wary of legitimate services being used as data exfiltration channels, such as those listed in the article (e.g. Telegra.ph Teletype), and report any suspicious activity to the relevant authorities.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TurlaTurla KazuarKazuar CVE-2025-8088CVE-2025-8088
Target & Sectors
BENELUX BENELUX DACH DACH governmentgovernment
Incident Timeline
‎January 2021
Threat actors used PteroSetup, an older Visual Basic Script (VBScript) weaponizer, to target Ukraine.
organisation PteroSetup
tactic T1059.005 - Visual Basic
organisation VBScript
organisation SFX
‎December 2022
Suspected development activity of malware began in December 2022.
‎December 2023
The Netherlands' VirusTotal service was compromised, allowing threat actors to upload a sample containing STOCKSTAY's separation of distinct role-based components.
target_region Netherlands
organisation VirusTotal
‎January 2025
Gamaredon further expanded its use of dead drops, tunnels, workers, dynamic DNS, and cloud storage to facilitate data exfiltration.
tactic T1059.001 - PowerShell
organisation PteroCache
threat_actor Turla
organisation GoFile
organisation Telegra.ph
organisation Dropbox
organisation DEV Community
organisation DNS
‎early 2025
Phishing actors used a malicious RDP file attachment in an email to target devices, allowing Turla-controlled infrastructure to be established.
tactic Phishing
threat_actor Turla
organisation RDP
‎November 2025
Threat actors used a newly discovered vulnerability in WinRAR to deliver an implant via RAR archives that exploited CVE-2025-8088, targeting Ukraine.
target_region Ukraine
tactic Phishing
vulnerability CVE-2025-8088
infrastructure Winrar
source_region Russian Federation
organisation CVE-2025
organisation Sandworm
‎2026/05/27
Kazuar exploited vulnerabilities in Kernel, Bridge, and Worker modules to launch attacks on Ukraine.
malware Kazuar
attribution Kernel, Bridge
attribution Worker
‎Jun 29, 2026
Gamaredon's attacks are known to rely on weaponizers like PteroLNK and PteroPaste, which infect USB drives and network drives with malicious LNK files.
organisation APT
organisation Gamaredon
organisation ESET
organisation HTML
organisation HTA
organisation PteroSand
organisation PteroPaste
organisation USB
organisation LNK
infrastructure Winrar
infrastructure Windows
organisation WinRAR
‎2026/06/29
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse.
organisation Gamaredon Expands Ukraine Attacks
organisation Cloud Service Abuse
threat_actor Turla
organisation Google
organisation New STOCKSTAY Backdoor Used
organisation HTA
organisation MSI
organisation GitHub
organisation RAR
organisation HTML Application
infrastructure Windows
organisation WebSocket
organisation Dir
organisation RmDir
organisation Image
organisation MultyTask
organisation Windows Registry
organisation RegDelete
organisation RegWrite
organisation Sysinfo
organisation UnpackArchive
organisation ChikenFresh
organisation IP
organisation STOCKSTAY
organisation IPC
organisation PDF
organisation WordPress
organisation KAZUAR
Tactical Metrics
Metrics
infrastructure
‎Winrar
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources