Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025) — Threadlinqs Intelligence
As of 2026-06-28, Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025) is a high-severity apt threat attributed to Gamaredon (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0968 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Gamaredon · Russia · ESPIONAGE
Gamaredon (FSB 18th Center / UAC-0010) conducted 35 confirmed spearphishing campaigns against Ukrainian governmental and military institutions in 2025, deploying six new PowerShell-based downloaders
Gamaredon, also tracked as Primitive Bear, ACTINIUM, UAC-0010, Earth Dahu, Pterodo, and Shuckworm, is a cyber-espionage threat group attributed with high confidence to the 18th Center for Information Security of Russia's Federal Security Service (FSB), believed to operate primarily from occupied Crimea. In 2025, the group dramatically expanded its toolset and operational tempo, conducting 35 distinct spearphishing campaigns against Ukrainian governmental and military institutions — with campaign volume significantly higher in H2 2025 than H1, indicating deliberate operational escalation aligned with the ongoing Ukraine conflict. Tool update cadence correlates with major Russian and Crimean holidays, suggesting the operators follow a Russian government work schedule.
The group introduced six new PowerShell-based downloaders in 2025, all part of its signature Ptero family: PteroDee (memory-resident PowerShell payload executor that avoids writing to disk), PteroCache (PowerShell fetcher for staged payloads), PteroDum (VBScript downloader using temporary disk writes with self-deletion after execution), PteroOdd (lightweight single-payload downloader using the Telegra.ph API, linked to Turla collaboration handoffs), PteroEffigy (cloud-storage C2 resolver using GoFile for next-stage C2 IP lookup), and PteroPaste (complex multi-function tool combining downloader, USB weaponizer, and persistence orchestrator capabilities). The group also resurrected PteroSetup, a VBScript-based weaponizer that targets installer files on fixed, removable, and network drives, and upgraded existing tools including PteroLNK, PteroPSLoad, PteroPSDoor, PteroVDoor, PteroBox, PteroSand, PteroStew, and PteroGraphin.
A landmark 2025 development was documented evidence of operational collaboration between Gamaredon (FSB Center 18) and Turla (FSB Center 16). Gamaredon serves as a broad-access provider — compromising hundreds to thousands of Ukrainian targets — while Turla cherry-picks only the highest-value victims for deployment of the Kazuar v2/v3 backdoor. Three distinct handoff chains were documented: in February 2025, PteroGraphin delivered a 3DES-encrypted Telegra.ph request leading to PteroOdd and DLL sideloading of Kazuar v3 (via vncutil64.exe and LaunchGFExperience.exe masquerading); in April 2025, PteroOdd followed by PteroEffigy fetched a scrss.ps1 payload from eset.ydns.eu leading to Kazuar v2 with agent label AGN-AB-26; and in June 2025, PteroPaste led through PowerShell to ekrn.ps1 fetched from 91.231.182.187, loading Kazuar v2 with agent label AGN-AB-27. Kazuar v3 has approximately 35% more code than v2 and operates in three roles: KERNEL, BRIDGE, and WORKER. Transport includes HTTPS, WebSockets, and Exchange Web Services (EWS), with XOR encryption using substitution-table-encrypted strings and environmental keying tied to the victim machine name.
C2 infrastructure evolved substantially in 2025. Gamaredon adopted heavy use of tunneling services to conceal operator infrastructure behind legitimate cloud providers: Cloudflare Tunnels (trycloudflare.com, from late 2024), Cloudflare Workers (workers.dev, added May 2025), Microsoft devtunnels (devtunnels.ms, added June 2025), and Loophole (loophole.site, added June 2025), with experimental use of loca.lt and bore.pub. Multi-hop C2 resolution chains were observed, for example: graph.org then Cloudflare Workers then Teletype then Telegra.ph then Telegram then operator server. The group also resurrected No-IP dynamic DNS domains for HTA-based spearphishing after years of using registered domains. Dead drop resolvers — public platforms used to store the current C2 IP address — expanded to include Telegram, Telegra.ph, Teletype, Rentry, Write.as, Dropbox, GoFile, DEV Community (dev.to), Mastodon, Lesma, Nopaste.net, and Paste.ee (pastee.dev). Data exfiltration shifted to S3-compatible cloud storage providers: Wasabi (wasabisys.com) in early 2025, Tebi (tebi.io) in mid-2025, and Intercolo (de-fra.i3storage
Weaknesses (CWE)
CWE-35, CWE-494
Target sectors: government administration, military, defense, intelligence
Target regions: ukraine, 151 - Eastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2025-8088, T1592, T1589, T1583, T1583, T1583, T1583, T1584, T1587, T1566, T1566