Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combination of spearphishing campaigns, custom weaponizers, and increasingly reliant on third-party services like tunnels and serverless workers to conceal its infrastructure and communication. Notably, Gamaredon collaborated with Turla and UAC-0099, and revived older techniques like DDNS and dead drops. The group’s tactics demonstrate a shift towards operational flexibility and a continued focus on leveraging readily available, legitimate services to evade detection and maintain operational security.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data