Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft

The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft
Share

Key points

  • ESET observed 35 distinct Gamaredon spear-phishing campaigns against Ukrainian targets in 2025, most in the second half of the year.
  • New loaders and stealers sit alongside long-running tools including PteroDash and GammaSteel.
  • GammaSteel variants this year pull browser-stored credentials and session cookies, letting attackers bypass password prompts entirely.
  • The group stages command-and-control traffic through legitimate cloud services including Telegram, Cloudflare tunnels, and Dropbox.
  • Phishing-resistant authenticators raise the cost at the login step, but a stolen live cookie is already past that gate.

What has Gamaredon been doing in 2025?

Slovakian firm ESET counted 35 distinct spear-phishing campaigns from the Russia-aligned group, also tracked as Armageddon and Shuckworm, against Ukrainian targets this year, with the bulk landing in the second half. Primary marks remain government bodies and defense entities. Delivery leans on LNK files, HTA droppers, and Office documents dressed as internal correspondence or military paperwork. We've followed the group since our 2 June report on GammaSteel being dropped through the WinRAR path-traversal bug CVE-2025-8088, and the toolset has kept branching since.

The malware family tree keeps adding branches. New loaders sit alongside established tools, and GammaSteel variants this year have been harvesting browser-stored credentials and session tokens. That matters because a session cookie lets an attacker walk past the password prompt and the second factor in one move.

Should you worry about the cloud-service abuse?

Yes, and it's the piece defenders underestimate. Telegram, Cloudflare tunnels, and Dropbox have appeared across campaign infrastructure this year. Blending into sanctioned SaaS traffic defeats naive egress filtering and complicates any DNS-based detection strategy that assumes attackers register their own domains. Blocking these services isn't realistic for most organisations, which is precisely why the technique keeps working.

Does MFA stop this?

Partly, and less than vendors tend to claim. Stolen session cookies bypass the second factor by design unless the relying party binds tokens to the originating device. That binding has never shipped at scale. Phishing-resistant authenticators such as WebAuthn and FIDO2 raise the cost meaningfully at the authentication step, but if the attacker already has a live cookie pulled from a browser profile after initial execution, you're in authorisation territory. The auth step is already behind you.

For IAM teams watching Ukraine-adjacent threat reporting, two things are worth doing now. Shorten refresh-token lifetimes and enforce rotation with reuse detection: a stolen refresh token valid for 90 days is a gift to the attacker. Bind sessions to device posture signals where your identity provider supports it, because conditional-access rules keyed only to impossible-travel are not enough against residential-proxy egress.

What does Gamaredon's persistence actually mean?

Gamaredon is not the most technically sophisticated Russian APT operating against Ukraine. It may be the most relentless. Its value to its sponsors looks like tempo rather than finesse, and tempo is exactly what grinds defenders down across a multi-year conflict. The tooling mutates just enough to stay ahead of static signatures. The lures keep looking like something a tired analyst would click on a Friday afternoon.

Campaign counts will almost certainly keep climbing into 2026. Watch whether token-binding approaches get any real traction among Ukrainian public-sector identity providers, and whether the group's C2 channel choices shift as cloud providers tighten abuse-detection on Telegram and Cloudflare infrastructure.

© 2026 Threat Vectr