Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Incidents: Gamaredon escalates attacks on Ukraine with new malware and cloud service abuse, targeting government and military entities through spear-phishing and exploit chains.
Deep Analysis and Expert Commentary
Gamaredon's 2025 campaign showcases a sophisticated blend of traditional and innovative tactics. The group's spear-phishing attacks often deliver malicious HTA downloaders via archive attachments or XHTML files, exploiting WinRAR vulnerabilities for persistence. Lateral movement is facilitated through USB and network drive infections using PteroLNK and PteroPaste. The introduction of six new PowerShell tools, including PteroDee and PteroEffigy, highlights the group's evolving toolkit. Abuse of legitimate services like Telegra.ph and GoFile for C2 communication complicates detection and disruption. Defenders should prioritize patching WinRAR, monitoring for unusual PowerShell activity, and restricting access to cloud storage services from critical systems.
Action Items
- Patch WinRAR to mitigate CVE-2025-8088 exploitation.
- Monitor and restrict PowerShell execution in memory to detect PteroDee and PteroCache.
- Implement network segmentation to limit lateral movement via USB and network drives.
Original Article Brief Intro
The Hacker News · 2026-06-29 · Incidents: Gamaredon escalates attacks on Ukraine with new malware and cloud service abuse, targeting government and military entities through spear-phishing and exploit chains.
Related Terms and Notes
CVE IDs
- CVE-2025-8088 — A patched flaw in WinRAR exploited by Gamaredon to place malicious HTA downloaders in the Windows Startup folder.
Techniques / TTPs
- Spear-Phishing
Context Notes
- APT
- Cloud Abuse
- Cloud Storage Abuse
- Gamaredon
- HTML Smuggling — A technique used to deliver malicious files by embedding them in seemingly harmless HTML or XHTML documents.
- Malware
- PowerShell Malware
- Ukrainian Cyber Attacks
- WinRAR Exploit