The Russian state-backed espionage group Gamaredon has expanded its cyber onslaught against Ukraine by developing new malware and leveraging cloud services to hide its command-and-control infrastructure. According to ESET Research, Gamaredon exclusively targeted Ukrainian governmental and military institutions throughout 2025, with a significant increase in spear-phishing campaigns in the second half of the year.

The group's reliance on third-party services has grown significantly, with tunnel services and serverless worker platforms becoming an increasingly important part of how it hides its real back-end infrastructure. Gamaredon operators have also developed and deployed six new malicious PowerShell tools, which are used for fetching and executing payloads in memory. Additionally, the file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services, making them the primary exfiltration method.

What Happened

Gamaredon's attacks are characterized by the use of archive attachments or XHTML files that employ HTML smuggling to deliver malicious HTA downloaders. These downloaders drop additional payloads, such as PteroSand, which is used for lateral movement and infection of USB drives and network drives with malicious LNK files. The group also uses PteroSetup, an older Visual Basic Script (VBScript) weaponizer first detected in January 2021, to scan USB and mapped network drives for legitimate installer files and replace them with 7z self-extracting archives containing the original installer and a malicious VBScript downloader.

The intrusion sequence is designed to be stealthy, with multiple script stages that can independently fetch and execute new payloads from remote infrastructure. This architecture turns the entire infection sequence into a stack of backdoors, making partial cleanups largely ineffective. The core of the new toolset is GammaWorm, a massive VBScript script that hides almost entirely inside NTFS Alternate Data Streams (ADS), an obscure Windows file system feature.

Background and Context

Gamaredon is attributed by the Security Service of Ukraine to the 18th Center of Information Security of Russia's FSB and is believed to operate out of occupied Crimea. The group has been tracked by ESET Research for its ongoing cyberespionage activities against Ukraine, with a focus on exfiltrating sensitive information and other critical data that could be exploited to support Russian interests in the war in Ukraine.

In 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor, underscoring the potential for coordinated cyberespionage campaigns among Russia-aligned groups. This cooperation highlights the complexity of modern cybersecurity threats and the need for industry professionals to stay informed about emerging trends and tactics.

Why It Matters to the Industry

The Gamaredon attacks demonstrate a sophisticated use of malware and cloud services, which can be adapted by other threat actors in the adult industry. The reliance on legitimate third-party services and the use of modular toolsets make it challenging for defenders to detect and mitigate these threats.

Industry professionals should take note of the following key factors: the increasing use of cloud storage services as exfiltration methods, the development of new malicious PowerShell tools, and the abuse of multiple legitimate messaging, social media, blogging, and paste services as dead drops. These tactics can be used to compromise adult industry platforms and steal sensitive data.

What Comes Next

The Gamaredon attacks serve as a reminder that cybersecurity threats are constantly evolving and adapting to new technologies and trends. Industry professionals must stay vigilant and informed about emerging threats, including the use of cloud services and modular toolsets.

ESET Research will continue to monitor and analyze Gamaredon's activities, providing insights into its tactics, techniques, and procedures (TTPs). This information can be used by industry professionals to improve their defenses against similar threats.

Key Facts

  • Gamaredon exclusively targeted Ukrainian governmental and military institutions throughout 2025.
  • The group developed and deployed six new malicious PowerShell tools in 2025.
  • PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo).
  • Gamaredon operators abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers and distributing payloads.
  • The group's reliance on third-party services has grown significantly in 2025.