Executive Summary
In 2025, the Russian-aligned APT group Gamaredon intensified its cyberespionage operations against Ukrainian governmental and military institutions. The group executed 35 distinct spearphishing campaigns, primarily in the latter half of the year, utilizing new PowerShell tools and resurrecting older VBScript weaponizers. Gamaredon also enhanced its data exfiltration methods by upgrading file stealers to support cloud storage services like Wasabi, Tebi, and Intercolo. To conceal its command and control infrastructure, the group increasingly relied on legitimate third-party services, including tunnels, workers, dynamic DNS, and platform-as-a-service offerings. Additionally, Gamaredon exploited various messaging, social media, blogging, and paste services as dead drops for distributing payloads and resolving C&C servers. This evolution in tactics underscores the group's adaptability and the persistent cyber threat it poses to Ukrainian institutions.
Why This Matters Now
Gamaredon's sophisticated use of legitimate services to mask its operations highlights the evolving nature of cyber threats, emphasizing the need for enhanced detection and mitigation strategies to protect sensitive information.
Attack Path Analysis
Gamaredon initiated the attack by sending spearphishing emails with weaponized RAR archives exploiting CVE-2025-8088 to Ukrainian governmental institutions. Upon opening the archive, a VBScript payload was executed, leading to the deployment of PowerShell-based malware for persistence and lateral movement. The malware established command and control channels by connecting to servers concealed behind Cloudflare tunnels and other third-party services. Sensitive data was exfiltrated to cloud storage services like Wasabi, Tebi, and Intercolo. The attack aimed to gather intelligence to support Russian interests in the ongoing conflict.
Kill Chain Progression
Initial Compromise
Description
Gamaredon sent spearphishing emails containing weaponized RAR archives exploiting CVE-2025-8088 to Ukrainian governmental institutions.
Related CVEs
CVE-2025-8088
CVSS 8.8A path traversal vulnerability in WinRAR allows attackers to execute arbitrary code by crafting malicious archive files.
Affected Products:
Rarlab WinRAR – < 7.13
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
Exploitation for Client Execution
PowerShell
Ingress Tool Transfer
Web Protocols
Valid Accounts
Obfuscated Files or Information
Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System and Software Security
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Primary target of Gamaredon cyberespionage operations with 35 spearphishing campaigns targeting governmental institutions for sensitive data exfiltration supporting Russian interests.
Military Industry
Direct targeting by Russia-aligned APT group exploiting lateral movement vulnerabilities and cloud storage exfiltration to compromise military intelligence and operations.
Information Technology/IT
Critical infrastructure risks from advanced tunneling, zero trust segmentation bypass, and encrypted traffic exploitation enabling sophisticated command and control operations.
Defense/Space
High-value target for FSB-attributed threat actor leveraging weaponizers, dead drops, and cloud services to extract defense intelligence supporting ongoing warfare.
Sources
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new allianceshttps://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/Verified
- CVE-2025-8088 - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-8088Verified
- Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerabilityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial compromise may still occur, CNSF would likely limit the attacker's ability to exploit the compromised system to reach other workloads.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the malware's ability to escalate privileges by restricting unauthorized access paths.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the malware's ability to move laterally by enforcing strict controls on internal communications.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the malware's ability to establish command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict outbound data transfer policies.
While some intelligence gathering may still occur, the overall impact would likely be reduced due to constrained attacker movement and data exfiltration capabilities.
Impact at a Glance
Affected Business Functions
- Government Communications
- Military Operations
- Data Security
Estimated downtime: 7 days
Estimated loss: $500,000
Sensitive governmental and military information, including classified documents and strategic plans.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Deploy Zero Trust Segmentation to restrict lateral movement within the network, limiting the spread of malware.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce East-West Traffic Security to monitor internal traffic and detect unauthorized communications.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.



