Executive Summary
In early 2025, a previously unseen collaboration between advanced persistent threat groups Gamaredon and Turla was discovered in Ukraine. Utilizing ESET telemetry, researchers identified co-compromises in which Gamaredon provided initial access using spearphishing and malicious PowerShell-based tools (such as PteroGraphin and PteroOdd), allowing Turla to deploy its exclusive Kazuar backdoor on select high-value targets. The attacks, attributed to Russian FSB-linked groups, targeted governmental entities and leveraged encrypted channels, PowerShell scripting, and multi-stage malware delivery via compromised web services and cloud platforms. Impact was mainly concentrated on the potential exfiltration of sensitive national intelligence.
This incident underscores a growing trend of threat actor collaboration within nation-state cyber operations, blurring lines between operational roles and increasing attack efficiency. The overlapping TTPs and use of novel access and persistence mechanisms signal heightened complexity in the Eastern European threat landscape, demanding urgent operational and strategic defensive improvements.
Why This Matters Now
This breach demonstrates an escalation in Russian-aligned APT synergy and technical sophistication, revealing both increased collaboration across threat groups and the ability to combine access vectors for maximizing impact against national critical infrastructure. With geopolitical tensions rising and threat actor tactics evolving rapidly, organizations face elevated risks that require immediate security modernization focused on detection, segmentation, and rapid response.
Attack Path Analysis
The attackers gained initial access likely through targeted spearphishing emails delivering malicious LNK files, followed by automated execution of custom PowerShell-based downloaders for persistence and privilege escalation. They maintained foothold and expanded access using custom scripts, leveraging compromised implants to move between systems and deploy collaborative tooling. Remote command and control were established via encrypted channels using legitimate web services such as Telegra.ph and cloudworker endpoints. Information on the system and running processes was exfiltrated to external C2 infrastructures, using both encrypted and masqueraded communications. Ultimately, the attackers achieved espionage objectives by maintaining persistent access to sensitive targets, deploying stealthy implants, and exfiltrating intelligence of strategic value.
Kill Chain Progression
Initial Compromise
Description
Gamaredon compromised target endpoints via spearphishing emails and malicious LNK files on removable drives, leading to the execution of PowerShell-based payload downloaders.
Related CVEs
CVE-2021-26855
CVSS 9.8Microsoft Exchange Server Remote Code Execution Vulnerability.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2021-26857
CVSS 7.8Microsoft Exchange Server Remote Code Execution Vulnerability.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2021-26858
CVSS 7.8Microsoft Exchange Server Remote Code Execution Vulnerability.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2021-27065
CVSS 7.8Microsoft Exchange Server Remote Code Execution Vulnerability.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Command and Scripting Interpreter: PowerShell
Hijack Execution Flow: DLL Side-Loading
Web Service
Deobfuscate/Decode Files or Information
System Information Discovery
Acquire Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Logging and Monitoring
Control ID: 10.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 9
CISA Zero Trust Maturity Model 2.0 – Identity, Device, and Network Segmentation
Control ID: 2.1-2.5
NIS2 Directive – Technical and Organizational Measures
Control ID: Art. 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Ukrainian governmental institutions face critical APT collaboration risks requiring enhanced east-west traffic security, zero trust segmentation, and threat detection capabilities.
Defense/Space
Defense sector vulnerabilities to FSB-aligned APT groups demand encrypted traffic protection, multicloud visibility, and inline IPS against advanced persistent threats.
Computer/Network Security
Security organizations must strengthen egress filtering, anomaly detection, and cloud native security fabric to counter sophisticated APT collaboration techniques.
Information Technology/IT
IT infrastructure requires enhanced Kubernetes security, secure hybrid connectivity, and cloud firewall capabilities against coordinated FSB cyberespionage campaigns.
Sources
- Gamaredon X Turla collabhttps://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/Verified
- ESET Research: Russian FSB-linked Gamaredon and Turla team up to target high-profile Ukrainian entitieshttps://www.globenewswire.com/news-release/2025/09/19/3153027/0/en/ESET-Research-Russian-FSB-linked-Gamaredon-and-Turla-team-up-to-target-high-profile-Ukrainian-entities.htmlVerified
- Two of the Kremlin’s most active hack groups are collaborating, ESET sayshttps://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
A multi-layered CNSF Zero Trust approach—especially leveraging microsegmentation, encrypted traffic enforcement, egress filtering, and anomaly/threat detection—would have provided critical barriers against each major phase of this campaign by blocking unauthorized access, constraining lateral spread, detecting anomalous PowerShell activity, and stopping outbound C2 and exfiltration traffic.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous script execution and suspicious PowerShell downloads would be detected and alerted.
Control: Kubernetes Security (AKF) / Zero Trust Segmentation
Mitigation: Policy and namespace restrictions would prevent privilege escalation and lateral movement between sensitive pods/namespaces.
Control: East-West Traffic Security
Mitigation: Lateral east-west communications between workloads would be tightly controlled and unauthorized flows blocked.
Control: Cloud Firewall (ACF) / Inline IPS (Suricata)
Mitigation: Outbound traffic to known malicious endpoints or cloud/telegra.ph APIs used for C2 would be detected or blocked inline.
Control: Egress Security & Policy Enforcement
Mitigation: Sensitive outbound data transfers to untrusted or unknown domains are blocked or flagged for investigation.
Centralized SOC visibility and automated enforcement reduce dwell time and persistence opportunities.
Impact at a Glance
Affected Business Functions
- Government Operations
- National Security
- Intelligence Services
Estimated downtime: 30 days
Estimated loss: $5,000,000
Potential exposure of classified government documents, intelligence reports, and sensitive communications.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy east-west microsegmentation and workload-based policies to block unauthorized lateral movement within cloud and hybrid environments.
- • Enforce strict egress controls and cloud firewall rules that include application-level FQDN filtering to disrupt malicious C2 and data exfiltration paths.
- • Integrate inline network anomaly detection and behavioral analytics to quickly detect and respond to covert tool usage such as custom PowerShell scripts.
- • Strengthen Kubernetes and container segmentation with pod identity enforcement and namespace allow-listing to prevent privilege escalation and unauthorized script execution.
- • Maintain centralized, multicloud network visibility and automated response capabilities to rapidly contain and investigate any detected intrusion attempts or anomalous workload behaviors.



