ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Gamaredon ramps up Ukraine spear-phishing with new malware and cloud abuse

Source headline: Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 month ago

Intelligence Summary

ESET reports the Russian APT group Gamaredon increased its operations against Ukraine through 2025. The activity included 35 spear-phishing campaigns targeting new victims, many launching in the latter half of the year. The intrusions involved both malware additions and abuse of cloud services for staging or delivery. This combination can help attackers evade controls and maintain persistence across environments. Organizations with Ukrainian exposure should review email security, harden cloud credentials, and hunt for Gamaredon indicators. Incident response teams should also validate outbound access and suspicious authentication patterns in cloud logs.

Recommended Action

Inventory where ESET runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#malware #apt #ukraine #cloud-abuse #gamaredon #spearphishing
Original reporting The Hacker News Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Open original source