Gamaredon escalates attacks on Ukraine: new malware and cloud service abuse

Colleagues, please note: Gamaredon has expanded its campaign against Ukraine — deploying new malware and actively abusing cloud services.
- ESET reports 35 spear‑phishing campaigns in 2025 targeting government and military entities.
- Attacks leverage HTML‑smuggling, HTA loaders, the WinRAR exploit (CVE‑2025‑8088) for persistence, and USB/network drive infection via LNK.
- New PowerShell tools have emerged, alongside extensive use of tunnels, serverless workers and cloud dead‑drops for C2.
Why it matters: adversaries are complicating detection and data exfiltration, endangering critical information.
What measures do you prioritize for defense?
#cybersecurity #APT #cloudsecurity #infosec

