Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Russian APT group Gamaredon continues to expand its cyber attacks against Ukraine, using new malware and cloud services.
Intelligence analysis by Qwen 2.5 (3B)

A Russian threat actor named Gamaredon has intensified its cyberattacks on Ukraine, employing fresh malware and leveraging cloud services for data exfiltration.
A bad guy named Gamaredon is using new tricks to try and get information from Ukraine. They're sending fake emails with hidden codes that can make computers do bad things. They're also using secret online places to hide their tricks better.
Analysis
A $60B Vote of Confidence
Gamaredon's persistence in Ukraine underscores its commitment to supporting Russian interests. The group has developed and deployed new tools over the past year, including PowerShell and VBScript payloads.
Why Cursor?
While Gamaredon took a break in January 2025, it resumed operations with significant efforts in the first half of that year, likely due to government-affiliated operators.
The Road Ahead
The group's reliance on legitimate services for data exfiltration and dead drop resolvers suggests its strategy remains flexible. However, this also makes its activities harder to disrupt.
Key points
- Gamaredon continues to target Ukraine with new malware
- Uses HTML smuggling and WinRAR vulnerabilities for delivery
- Expands use of cloud services for data exfiltration
- Developed six new PowerShell tools in 2025
- Relies on legitimate online services for hiding its activities
If Gamaredon's tactics change, it could mean they are getting less active or have new strategies.
The group might continue its attacks and use more hidden services, making it harder for Ukraine to stop them.



