ESET Details Gamaredon’s 2025 Cyberespionage Tactics Against Ukraine

Summary
ESET’s analysis of Gamaredon in 2025 describes 35 spearphishing campaigns against Ukrainian institutions, new malware tools, exploitation of a WinRAR vulnerability, cooperation with Turla, and expanded use of legitimate services for C&C and data exfiltration.
Key points
- Gamaredon targeted Ukrainian government and military institutions throughout 2025, with ESET identifying 35 spearphishing campaigns.
- Campaigns commonly used archive or XHTML attachments to deliver HTA downloaders; from September, the group abused WinRAR vulnerability CVE-2025-8088 to place downloaders in victims’ Startup folders for persistence.
- The group introduced six PowerShell tools and revived the PteroSetup VBScript weaponizer, which disguises malicious code as legitimate installers.
- Gamaredon expanded its use of tunnels, serverless workers, DDNS, and legitimate online services as dead drops to conceal or relay command-and-control information and payloads.
- Updated PteroPSDoor and PteroVDoor stealers increasingly exfiltrated files to S3-compatible cloud storage; Intercolo was the primary destination by December.
- ESET documented early-2025 cooperation between Gamaredon and the Russia-aligned Turla group.
Article Details
- Attack Vectors
- ESET observed 35 spearphishing campaigns against new targets in 2025, predominantly using archive attachments or XHTML files with HTML smuggling to deliver malicious HTA downloaders.
- Some spearphishing campaigns probably used malicious hyperlinks instead of attachments.
- From 2025-09-26, attackers exploited an archive-extraction vulnerability to place malicious HTA downloaders in victims' Startup folders for execution at the next login.
- Custom weaponizers modified USB drives, mapped network drives, and software installers to spread beyond initially compromised systems.
- An installer weaponizer replaced installer-like executables with malicious self-extracting archives containing both the original installer and a malicious downloader.
- Legitimate online services supplied staged payloads, command-and-control information, and cloud-storage configuration data; tunnels and serverless workers concealed backend infrastructure.
- File stealers uploaded stolen data to third-party cloud storage, which became the primary exfiltration method.
- Defensive Notes
- Monthly counts of unique HTA downloaders represent minimum spearphishing activity: one downloader can target multiple people, and individuals can be targeted repeatedly.
- Dead drops complicate blocking because they use legitimate, widely used services that defenders may be reluctant to block outright.
- Dead-drop values increasingly pointed to tunnels or workers rather than exposing backend command-and-control servers directly.
- Multiple intermediary services supplied primary and fallback communication paths, making infrastructure disruption more difficult.
- Cloud-storage exfiltration helped malicious traffic blend with legitimate storage-provider access.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationEarly PteroPaste versions staged encrypted payloads through Rentry; later versions retrieved encrypted command-and-control hostnames.T1027.006 · HTML SmugglingXHTML files used HTML smuggling to deliver malicious HTA downloaders.T1036 · MasqueradingPteroSetup's replacement archives appeared to be legitimate installers and launched the original installer alongside malicious code.T1059.001 · PowerShellGamaredon deployed six new PowerShell malware tools; PteroDee and PteroCache fetched and executed PowerShell payloads in memory.T1059.005 · Visual BasicPteroDum wrote VBScript payloads to disk and executed them; PteroSetup also delivered a malicious VBScript downloader.T1070.004 · File DeletionPteroDum deleted temporarily written VBScript payloads after executing them.T1080 · Taint Shared ContentCustom weaponizers modified mapped network drives for lateral movement, and PteroSetup replaced installer-like executables on network drives with malicious archives.T1083 · File and Directory DiscoveryPteroSetup scanned fixed, removable, and network drives for installer-like executable files.T1090.002 · External ProxyGamaredon concealed command-and-control servers behind third-party tunnels and workers, sometimes using multiple services as primary and fallback communication paths.T1091 · Replication Through Removable MediaGamaredon's weaponizers modified USB drives to spread beyond compromised systems; PteroPaste included a USB weaponizer.T1102.001 · Dead Drop ResolverMalware retrieved staged command-and-control information from legitimate messaging, blogging, social, paste, and storage services used as dead drops.T1105 · Ingress Tool TransferHTA downloaders fetched PteroSand and additional payloads, while new downloaders retrieved PowerShell or VBScript payloads.T1140 · Deobfuscate/Decode Files or InformationLater PteroPaste versions retrieved an encrypted command-and-control hostname from Dropbox and decrypted it locally.T1203 · Exploitation for Client ExecutionBeginning on 2025-09-26, Gamaredon abused CVE-2025-8088 in WinRAR to place its malicious HTA downloader in victims' Startup folders.T1204.002 · Malicious FileRunning an installer replaced by PteroSetup launched both the expected installer and a malicious VBScript downloader.T1547.001 · Registry Run Keys / Startup FolderMalicious HTA downloaders placed in the Startup folder executed at the victim's next login.T1566.001 · Spearphishing AttachmentMost observed spearphishing campaigns delivered archive attachments or XHTML files that led to malicious HTA downloaders.T1566.002 · Spearphishing LinkESET observed campaigns that probably used malicious hyperlinks instead of attachments.T1567.002 · Exfiltration to Cloud StoragePteroPSDoor and PteroVDoor uploaded stolen files to Wasabi, Tebi, and Intercolo; PteroBox uploaded files to Dropbox, with one variant using rclone.
CVE
Threat Actors
GamaredonRussia-aligned cyberespionage group that ESET observed exclusively targeting governmental and military institutions in Ukraine during 2025. The SSU attributes it to the 18th Center of Information Security of Russia's FSB; the group is believed to operate from occupied Crimea.InvisiMoleThreat actor discovered and named by ESET that previously collaborated with Gamaredon.SandwormReceived validated targets from UAC-0099 for follow-up activity, according to ESET's observations of cooperation among Russia-aligned actors.TurlaRussia-aligned threat actor linked to the FSB that ESET found collaborating with Gamaredon in early 2025.UAC-0099Russia-aligned group that ESET observed conducting initial access operations in 2025 and transferring validated targets to Sandworm.
Malware
PteroBoxImportant updates to previously known tools such as PteroLNK, PteroPSLoad, PteroPSDoor, PteroVDoor, and PteroBox can be found in the white paper.PteroCachePteroDee and PteroCache are straightforward PowerShell downloaders for fetching and executing PowerShell payloads in memory.PteroDeePteroDee and PteroCache are straightforward PowerShell downloaders for fetching and executing PowerShell payloads in memory.PteroDumPteroDum serves a similar purpose, but for VBScript payloads, writing them temporarily to disk, executing them, and then deleting them.PteroEffigyPteroEffigy is another lightweight downloader, notable mainly for using the GoFile cloud storage service to obtain the next C&C server.PteroLNKImportant updates to previously known tools such as PteroLNK, PteroPSLoad, PteroPSDoor, PteroVDoor, and PteroBox can be found in the white paper.PteroOddPteroOdd is a tiny downloader used to retrieve a single PowerShell payload via the Telegra.ph API, and based on what we observed, it appears to have been used mainly in cases connected to Gamaredon’s collaboration withPteroPasteThe standout among the new tools is PteroPaste, which is considerably more complex than the others.PteroPSDoorThe file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo), which became the primary exfiltration method.PteroPSLoadImportant updates to previously known tools such as PteroLNK, PteroPSLoad, PteroPSDoor, PteroVDoor, and PteroBox can be found in the white paper.PteroSandAs in previous years, most campaigns used archive attachments or XHTML files employing HTML smuggling to deliver malicious HTA downloaders, which in turn fetched the VBScript downloader PteroSand and additional payloads.PteroSetupGamaredon operators developed and deployed six new malicious PowerShell tools, which we analyze in our white paper, and resurrected an old VBScript weaponizer – PteroSetup.PteroVDoorThe file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo), which became the primary exfiltration method.
Vendors
Clever CloudIn parallel, we observed Gamaredon abuse platform-as-a-service offerings from Clever Cloud (cleverapps.io) and Supabase (supabase.co) in several campaigns, suggesting that the group is still actively looking for cheap,CloudflareBy the end of 2024, Gamaredon was already relying heavily on Cloudflare tunnels (trycloudflare.com) to conceal its infrastructure, and in 2025 it expanded that approach further.DropboxLater versions moved away from that approach and instead retrieve an encrypted C&C hostname from Dropbox, decrypt it locally, and then connect to infrastructure hidden behind tunnel services.GoFilePteroEffigy is another lightweight downloader, notable mainly for using the GoFile cloud storage service to obtain the next C&C server.IntercoloThe file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo), which became the primary exfiltration method.LoopholeIn May, we began seeing the group hide C&C servers behind Cloudflare workers (workers.dev), and in June it added Microsoft’s devtunnels.ms and Loophole (loophole.site).MicrosoftIn May, we began seeing the group hide C&C servers behind Cloudflare workers (workers.dev), and in June it added Microsoft’s devtunnels.ms and Loophole (loophole.site).No-IPAfter several years of relying more heavily on registered domains, the group again began using No-IP domains across multiple tools, especially in HTA downloaders delivered in spearphishing campaigns.Supabasewe observed Gamaredon abuse platform-as-a-service offerings from Clever Cloud (cleverapps.io) and Supabase (supabase.co) in several campaigns, suggesting that the group is still actively looking for cheap,TebiThe file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo), which became the primary exfiltration method.WasabiThe file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo), which became the primary exfiltration method.