Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gamaredon’s Ukraine Cyber Attacks Intensify with New Tactics

Gamaredon’s Ukraine Cyber Attacks Intensify with New Tactics

Posted on June 29, 2026 By CWS

A Russian advanced persistent threat group, known as Gamaredon, has been intensifying its cyber attacks on Ukraine by expanding its malware arsenal and exploiting cloud services. Throughout 2025, cybersecurity experts observed a surge in spear-phishing campaigns targeting Ukrainian government and military entities, marking a significant escalation in cyber warfare tactics.

Increasing Spear-Phishing Campaigns

According to Slovakian cybersecurity firm ESET, Gamaredon orchestrated 35 spear-phishing campaigns in 2025, primarily in the latter half of the year. These attacks aimed to extract sensitive information to further Russian interests amid ongoing conflicts. The group utilized various methods, including archive attachments and XHTML files, to deliver malicious payloads.

A notable aspect of these campaigns was the exploitation of a patched WinRAR vulnerability (CVE-2025-8088) to deploy harmful software into victims’ systems. This technique allowed the malware to persistently execute upon the next system login, thereby strengthening the compromise’s foothold.

Enhanced Malware Tactics

Gamaredon’s attacks have become increasingly sophisticated, employing tools like PteroLNK and PteroPaste to spread malware through infected USB and network drives. Additionally, they revived PteroSetup, a Visual Basic Script weaponizer, to replace legitimate installer files with malicious scripts, further complicating detection efforts.

In 2025, the group’s dependency on third-party services grew, integrating tunnel services and serverless platforms to obscure their infrastructure. This shift highlights a strategic evolution in maintaining operational security and resilience against countermeasures.

Expansion of Custom Malware Arsenal

The introduction of six new PowerShell tools demonstrated Gamaredon’s commitment to broadening its custom malware capabilities. These tools included PteroDee and PteroCache for PowerShell payload execution, and PteroDum for VBScript payloads. Furthermore, PteroOdd leveraged the Telegra.ph API, suggesting possible collaboration with other cyber actors like Turla.

Gamaredon’s approach also involved utilizing legitimate services as exfiltration channels and dead drop resolvers, complicating efforts to trace and disrupt their operations. Services like Dropbox, Telegra.ph, and GoFile were among those exploited to facilitate data extraction and command-and-control communication.

ESET researcher Zoltán Rusnák noted that while Gamaredon paused operations around major Russian holidays, their activities were marked by frequent updates and creative use of online services, enhancing their operational flexibility.

As these cyber threats continue to evolve, understanding Gamaredon’s tactics is crucial for developing effective countermeasures and protecting critical infrastructure in Ukraine and beyond.

The Hacker News Tags:APT group, C2 Server, cloud security, cloud services, cyber attacks, Cybersecurity, data exfiltration, ESET, Gamaredon, Malware, PowerShell, Russia, spear-phishing, Ukraine

Post navigation

Previous Post: AI Transforms Red-Team Tool Creation with Mythic Agents
Next Post: DCloud Uni-App Framework Fuels Global Crypto Scams

Related Posts

Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools The Hacker News
40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials 40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials The Hacker News
Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed The Hacker News
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials The Hacker News
CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git The Hacker News
ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket
  • NAIC Confirms Data Breach in Oracle PeopleSoft Hack
  • DCloud Uni-App Framework Fuels Global Crypto Scams

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket
  • NAIC Confirms Data Breach in Oracle PeopleSoft Hack
  • DCloud Uni-App Framework Fuels Global Crypto Scams

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark