#gamaredon
GamaCopy Mimics Gamaredon Tactics in Cyber Espionage Targeting Russian Entities
GamaCopy Mimics Gamaredon Tactics in Cyber Espionage Targeting Russian Entities
thehackernews.com
January 27, 2025 at 9:17 AM
russian cyberspies Gamaredon has been discovered using two Android spyware families named 'BoneSpy' and 'PlainGnome' to spy on and steal data from mobile devices.

www.bleepingcomputer.com/news/securit...
Russian cyberspies target Android users with new spyware
Russian cyberspies Gamaredon has been discovered using two Android spyware families named 'BoneSpy' and 'PlainGnome' to spy on and steal data from mobile devices.
www.bleepingcomputer.com
December 14, 2024 at 6:29 PM
Russian cyberspies Gamaredon has been discovered using two Android spyware families named 'BoneSpy' and 'PlainGnome' to spy on and steal data from mobile devices. #Android #spyware #Russian www.bleepingcomputer.com/news/securit...
Russian cyberspies target Android users with new spyware
Russian cyberspies Gamaredon has been discovered using two Android spyware families named 'BoneSpy' and 'PlainGnome' to spy on and steal data from mobile devices.
www.bleepingcomputer.com
December 13, 2024 at 9:43 PM
Two of the world’s most prolific state-linked cybercrime groups — Russia’s Gamaredon and North Korea’s Lazarus collective — have been spotted sharing resources, new research showed yesterday.
Russia, North Korea partner on cybercrime, researchers warn
Findings suggest a new level of coordination between Moscow and Pyongyang.
www.politico.eu
November 21, 2025 at 11:11 AM
#ESETresearch has observed #Gamaredon exploiting CVE-2025-8088 (#WinRAR path traversal) in an ongoing spearphishing campaign. This vulnerability allows arbitrary file write via crafted RAR archives. 1/6
September 26, 2025 at 1:13 PM
For the past decade, this group of FSB hackers—including “traitor” Ukrainian intelligence officers—has used a grinding barrage of intrusion campaigns to make life hell for their former countrymen and cybersecurity defenders. www.wired.com/story/gamare...
Gamaredon: The Turncoat Spies Relentlessly Hacking Ukraine
For the past decade, this group of FSB hackers—including “traitor” Ukrainian intelligence officers—has used a grinding barrage of intrusion campaigns to make life hell for their former countrymen...
www.wired.com
April 14, 2025 at 10:05 AM
Did you know that I host a podcast for #ESET?

Unlike typical state-backed actors, #Gamaredon is noisy, active, and evolves its tactics constantly. Join me with #ESET experts Zoltán Rusnák & Robert Lipovsky as they uncover this Russia-aligned group’s actions.

www.welivesecurity.com/en/podcasts/...
ESET Research Podcast: Gamaredon
ESET researchers introduce the Gamaredon APT group, detailing its typical modus operandi, unique victim profile, extensive collection of tools and social engineering tactics and even its estimated geo...
www.welivesecurity.com
November 14, 2024 at 7:19 PM
#ESETresearch has conducted a comprehensive technical analysis of new malicious tools and significant updates observed in 2024 in the arsenal of the Russia-aligned #Gamaredon #APTgroup targeting Ukraine🇺🇦. www.welivesecurity.com/en/eset-rese... 1/9
Gamaredon in 2024: Cranking out spearphishing campaigns against Ukraine with an evolved toolset
ESET Research analyzes Gamaredon’s updated cyberespionage toolset, new stealth-focused techniques, and aggressive spearphishing operations observed throughout 2024.
www.welivesecurity.com
July 2, 2025 at 10:49 AM
We at Wired put together six stories on lesser known hacker groups who have quietly become some of the most harmful in the world.

Case in point: The turncoat Ukrainian spies working for Russia who some analysts say are the top cyberespionage threat to Ukraine today. www.wired.com/story/gamare...
Gamaredon: The Turncoat Spies Relentlessly Hacking Ukraine
For the past decade, this group of FSB hackers—including “traitor” Ukrainian intelligence officers—has used a grinding barrage of intrusion campaigns to make life hell for their former countrymen and ...
www.wired.com
April 14, 2025 at 9:00 PM
#ESETresearch has discovered the first known cases of collaboration between Gamaredon and Turla, in Ukraine. Both groups are affiliated with the FSB, Russia’s main domestic intelligence and security agency. www.welivesecurity.com/en/eset-rese...
1/3
Gamaredon X Turla collab
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
www.welivesecurity.com
September 19, 2025 at 9:27 AM
Gamaredon amplía sus ataques en Ucrania con nuevo malware y abuso de servicios en la nube

#Ciberseguridad #Seguridad #Tecnología #LaiaDesk
Gamaredon amplía sus ataques en Ucrania con nuevo malware y abuso de servicios en la nube
El grupo de ciberespionaje ruso conocido como Gamaredon ha intensificado sus ataques contra Ucrania durante 2025, incorporando nuevas herramientas maliciosas y abusando de servicio…
laiadesk.com
September 23, 2026 at 6:20 PM
russian state-backed hacking group Gamaredon (aka “Shuckworm”) has been targeting a military mission of a Western country in #Ukraine in attacks likely deployed from removable drives.

www.bleepingcomputer.com/news/securit...
Russian hackers attack Western military mission using malicious drive
The Russian state-backed hacking group Gamaredon (aka "Shuckworm") has been targeting a military mission of a Western country in Ukraine in attacks likely deployed from removable drives.
www.bleepingcomputer.com
April 10, 2025 at 9:24 PM
Russian cyberspies Gamaredon has been discovered using two Android spyware families named 'BoneSpy' and 'PlainGnome' to spy on and steal data from mobile devices.
Russian cyberspies target Android users with new spyware
Russian cyberspies Gamaredon has been discovered using two Android spyware families named 'BoneSpy' and 'PlainGnome' to spy on and steal data from mobile devices.
www.bleepingcomputer.com
December 13, 2024 at 5:43 PM
🧵Mit "BoneSpy" und "PlainGnome" wurden zwei neue Spyware-Familien auf Android entdeckt, die der russischen Gruppe "Gamaredon" (verbunden mit dem FSB) zugeschrieben werden. (1|2)
www.lookout.com/threat-intel...
Lookout Discovers PlainGnome and Bonespy Russian Android spyware | Threat Intel
Researchers at the Lookout Threat Lab have discovered two Android surveillance families dubbed BoneSpy and PlainGnome attributed to Russian cyber espionage group Gamaredon
www.lookout.com
December 14, 2024 at 6:35 AM
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams.
securityaffairs.com
June 4, 2026 at 11:34 AM
🇷🇺 🇺🇦 #Cybersecurity researchers have discerned evidence of two Russian hacking groups Gamaredon and Turla collaborating together to target and compromise Ukrainian entities.

www.welivesecurity.com/en/eset-rese...

#russia #ukraine
Gamaredon X Turla collab
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
www.welivesecurity.com
September 19, 2025 at 9:14 AM
The Russia-backed threat group Gamaredon, typically known for spreading malware via phishing emails, recently appeared to have used an infected removable drive to target a Ukraine-based military mission of an unnamed Western country, researchers said.

✍️ @darynant.bsky.social
Tainted drive appears to be source of malware attack on Western military mission in Ukraine
Researchers at Symantec said the Russia-linked group known as Gamaredon appears to have departed from its usual email phishing tactics in hacking a Western military mission in Ukraine.
therecord.media
April 11, 2025 at 9:20 AM
#Gamaredon APT Alert: Russian-backed group now uses troop movement lures to spread Remcos RAT via DLL sideloading.
Targets: Ukrainian govt & military. Critical to block malicious .LNK files & audit DLL loads.
Tactics: securityonline.info/gamaredon-ex...
Gamaredon Exploits Troop Movement Lures to Spread Remcos via DLL Sideloading
Learn how the Remcos backdoor malware is being distributed through Windows shortcut files in a targeted campaign.
securityonline.info
March 31, 2025 at 6:47 AM
ClearSky has spotted the Gamaredon APT deploying the GamaWiper in data-wiping attacks at Ukrainian organizations.

The attacks leveraged a WinRAR vulnerability tracked as CVE-2025-80880.

nitter.catsarch.com/ClearskySec/...
December 2, 2025 at 3:40 PM
C’est une 1e: nous avons documenté une collaboration visible entre Turla et Gamaredon, 2 groupes de hackers liés au FSB, qui jusqu’alors opéraient tjrs en vase clos. Les difficultés en 🇺🇦 forceraient-elles les services russes à tempérer leurs rivalités internes? www.welivesecurity.com/en/eset-rese...
Gamaredon X Turla collab
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
www.welivesecurity.com
September 19, 2025 at 4:55 PM