Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gamaredon’s Ukraine Cyber Attacks Intensify with New Tactics

Gamaredon’s Ukraine Cyber Attacks Intensify with New Tactics

Posted on June 29, 2026 By CWS

A Russian advanced persistent threat group, known as Gamaredon, has been intensifying its cyber attacks on Ukraine by expanding its malware arsenal and exploiting cloud services. Throughout 2025, cybersecurity experts observed a surge in spear-phishing campaigns targeting Ukrainian government and military entities, marking a significant escalation in cyber warfare tactics.

Increasing Spear-Phishing Campaigns

According to Slovakian cybersecurity firm ESET, Gamaredon orchestrated 35 spear-phishing campaigns in 2025, primarily in the latter half of the year. These attacks aimed to extract sensitive information to further Russian interests amid ongoing conflicts. The group utilized various methods, including archive attachments and XHTML files, to deliver malicious payloads.

A notable aspect of these campaigns was the exploitation of a patched WinRAR vulnerability (CVE-2025-8088) to deploy harmful software into victims’ systems. This technique allowed the malware to persistently execute upon the next system login, thereby strengthening the compromise’s foothold.

Enhanced Malware Tactics

Gamaredon’s attacks have become increasingly sophisticated, employing tools like PteroLNK and PteroPaste to spread malware through infected USB and network drives. Additionally, they revived PteroSetup, a Visual Basic Script weaponizer, to replace legitimate installer files with malicious scripts, further complicating detection efforts.

In 2025, the group’s dependency on third-party services grew, integrating tunnel services and serverless platforms to obscure their infrastructure. This shift highlights a strategic evolution in maintaining operational security and resilience against countermeasures.

Expansion of Custom Malware Arsenal

The introduction of six new PowerShell tools demonstrated Gamaredon’s commitment to broadening its custom malware capabilities. These tools included PteroDee and PteroCache for PowerShell payload execution, and PteroDum for VBScript payloads. Furthermore, PteroOdd leveraged the Telegra.ph API, suggesting possible collaboration with other cyber actors like Turla.

Gamaredon’s approach also involved utilizing legitimate services as exfiltration channels and dead drop resolvers, complicating efforts to trace and disrupt their operations. Services like Dropbox, Telegra.ph, and GoFile were among those exploited to facilitate data extraction and command-and-control communication.

ESET researcher Zoltán Rusnák noted that while Gamaredon paused operations around major Russian holidays, their activities were marked by frequent updates and creative use of online services, enhancing their operational flexibility.

As these cyber threats continue to evolve, understanding Gamaredon’s tactics is crucial for developing effective countermeasures and protecting critical infrastructure in Ukraine and beyond.

The Hacker News Tags:APT group, C2 Server, cloud security, cloud services, cyber attacks, Cybersecurity, data exfiltration, ESET, Gamaredon, Malware, PowerShell, Russia, spear-phishing, Ukraine

Post navigation

Previous Post: AI Transforms Red-Team Tool Creation with Mythic Agents
Next Post: DCloud Uni-App Framework Fuels Global Crypto Scams

Related Posts

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE The Hacker News
Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat The Hacker News
DOM-Based Extension Clickjacking Exposes Popular Password Managers to Credential and Data Theft DOM-Based Extension Clickjacking Exposes Popular Password Managers to Credential and Data Theft The Hacker News
Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution The Hacker News
Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine The Hacker News
Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NAIC Confirms Data Breach in Oracle PeopleSoft Hack
  • DCloud Uni-App Framework Fuels Global Crypto Scams
  • DCloud Uni-App Framework Fuels Global Crypto Scams
  • Gamaredon’s Ukraine Cyber Attacks Intensify with New Tactics
  • AI Transforms Red-Team Tool Creation with Mythic Agents

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NAIC Confirms Data Breach in Oracle PeopleSoft Hack
  • DCloud Uni-App Framework Fuels Global Crypto Scams
  • DCloud Uni-App Framework Fuels Global Crypto Scams
  • Gamaredon’s Ukraine Cyber Attacks Intensify with New Tactics
  • AI Transforms Red-Team Tool Creation with Mythic Agents

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark