Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
Russian APT Gamaredon Upgrades Arsenal with Six New (TL-2026-0968) is a high-severity advanced persistent threat campaign, first published 2026-06-28. It is attributed to Gamaredon (Russia) with high confidence, affects RARLAB WinRAR, references 1 CVE (CVE-2025-8088), maps to 35 MITRE ATT&CK techniques (T1005, T1012, T1025), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-0968
- Threat ID
- TL-2026-0968
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-06-28
- Last reviewed
- 2026-06-28
- Attribution
- Gamaredon
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, military, defense, intelligence
- Target regions
- ukraine, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in Russian APT Gamaredon Upgrades Arsenal with Six New
Malware and tooling: PteroDee, PteroEffigy, PteroPaste
Gamaredon (FSB 18th Center / UAC-0010) conducted 35 confirmed spearphishing campaigns against Ukrainian governmental and military institutions in 2025, deploying six new PowerShell-based downloaders (PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, PteroPaste) and concealing C2 behind Cloudflare tunnels, Cloudflare Workers, and Microsoft devtunnels. The group collaborated with Turla (FSB Center 16) to deliver Kazuar v2/v3 backdoors to cherry-picked high-value targets, and from September 2025 exploited CVE-2025-8088 (WinRAR path traversal, CVSS 8.8) to plant HTA downloaders in Windows Startup folders for persistent access across Ukrainian government and military networks.
How Russian APT Gamaredon Upgrades Arsenal with Six New works
Gamaredon, also tracked as Primitive Bear, ACTINIUM, UAC-0010, Earth Dahu, Pterodo, and Shuckworm, is a cyber-espionage threat group attributed with high confidence to the 18th Center for Information Security of Russia's Federal Security Service (FSB), believed to operate primarily from occupied Crimea. In 2025, the group dramatically expanded its toolset and operational tempo, conducting 35 distinct spearphishing campaigns against Ukrainian governmental and military institutions — with campaign volume significantly higher in H2 2025 than H1, indicating deliberate operational escalation aligned with the ongoing Ukraine conflict. Tool update cadence correlates with major Russian and Crimean holidays, suggesting the operators follow a Russian government work schedule.
The group introduced six new PowerShell-based downloaders in 2025, all part of its signature Ptero family: PteroDee (memory-resident PowerShell payload executor that avoids writing to disk), PteroCache (PowerShell fetcher for staged payloads), PteroDum (VBScript downloader using temporary disk writes with self-deletion after execution), PteroOdd (lightweight single-payload downloader using the Telegra.ph API, linked to Turla collaboration handoffs), PteroEffigy (cloud-storage C2 resolver using GoFile for next-stage C2 IP lookup), and PteroPaste (complex multi-function tool combining downloader, USB weaponizer, and persistence orchestrator capabilities). The group also resurrected PteroSetup, a VBScript-based weaponizer that targets installer files on fixed, removable, and network drives, and upgraded existing tools including PteroLNK, PteroPSLoad, PteroPSDoor, PteroVDoor, PteroBox, PteroSand, PteroStew, and PteroGraphin.
A landmark 2025 development was documented evidence of operational collaboration between Gamaredon (FSB Center 18) and Turla (FSB Center 16). Gamaredon serves as a broad-access provider — compromising hundreds to thousands of Ukrainian targets — while Turla cherry-picks only the highest-value victims for deployment of the Kazuar v2/v3 backdoor. Three distinct handoff chains were documented: in February 2025, PteroGraphin delivered a 3DES-encrypted Telegra.ph request leading to PteroOdd and DLL sideloading of Kazuar v3 (via vncutil64.exe and LaunchGFExperience.exe masquerading); in April 2025, PteroOdd followed by PteroEffigy fetched a scrss.ps1 payload from eset.ydns.eu leading to Kazuar v2 with agent label AGN-AB-26; and in June 2025, PteroPaste led through PowerShell to ekrn.ps1 fetched from 91.231.182.187, loading Kazuar v2 with agent label AGN-AB-27. Kazuar v3 has approximately 35% more code than v2 and operates in three roles: KERNEL, BRIDGE, and WORKER. Transport includes HTTPS, WebSockets, and Exchange Web Services (EWS), with XOR encryption using substitution-table-encrypted strings and environmental keying tied to the victim machine name.
C2 infrastructure evolved substantially in 2025. Gamaredon adopted heavy use of tunneling services to conceal operator infrastructure behind legitimate cloud providers: Cloudflare Tunnels (trycloudflare.com, from late 2024), Cloudflare Workers (workers.dev, added May 2025), Microsoft devtunnels (devtunnels.ms, added June 2025), and Loophole (loophole.site, added June 2025), with experimental use of loca.lt and bore.pub. Multi-hop C2 resolution chains were observed, for example: graph.org then Cloudflare Workers then Teletype then Telegra.ph then Telegram then operator server. The group also resurrected No-IP dynamic DNS domains for HTA-based spearphishing after years of using registered domains. Dead drop resolvers — public platforms used to store the current C2 IP address — expanded to include Telegram, Telegra.ph, Teletype, Rentry, Write.as, Dropbox, GoFile, DEV Community (dev.to), Mastodon, Lesma, Nopaste.net, and Paste.ee (pastee.dev). Data exfiltration shifted to S3-compatible cloud storage providers: Wasabi (wasabisys.com) in early 2025, Tebi (tebi.io) in mid-2025, and Intercolo (de-fra.i3storage.com) as the primary exfiltration endpoint by December 2025, with rclone used in newer variants alongside PteroBox's continued Dropbox uploads. PaaS platforms Clever Cloud (cleverapps.io) and Supabase (supabase.co) were used for staging and victim fingerprint beaconing respectively.
From September 26, 2025, Gamaredon began exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR <= 7.12 on Windows (CVSS 3.1: 8.8 HIGH, CVSS 4.0: 8.4 HIGH), discovered by ESET researchers. The attack chain delivers a weaponized XHTML file via spearphishing using HTML smuggling; the embedded RAR archive exploits the path traversal flaw to silently write an HTA downloader file to the Windows Startup folder (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\). On next user login, mshta.exe auto-executes the HTA, triggering a four-stage VBScript cascade (GammaPhish to GammaLoad to GammaSteel exfiltration). Persistence is reinforced via three scheduled tasks (DiskDiagnosticDataCollector, SilentCleanup, SmartRetry running at 7-10 minute intervals) and a RunOnce registry key that recreates itself on each login. NTFS alternate data streams (ADS) are used for invisible payload storage in %APPDATA% directories. CISA added CVE-2025-8088 to the Known Exploited Vulnerabilities catalog on August 12, 2025, with a remediation deadline of September 2, 2025. Historical collaboration with InvisiMole was noted; UAC-0099 was also observed conducting initial access with validated high-value targets transferred to Sandworm for follow-up in Q2-Q3 2025.
MITRE ATT&CK techniques used in TL-2026-0968
Collection
T1005 Data from Local System; T1025 Data from Removable Media
Discovery
T1012 Query Registry; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1135 Network Share Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1564 Hide Artifacts; T1574 Hijack Execution Flow
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1568 Dynamic Resolution; T1573 Encrypted Channel
Lateral Movement
T1080 Taint Shared Content; T1091 Replication Through Removable Media
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
stealth
T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1592 Gather Victim Host Information
Affected products and versions in Russian APT Gamaredon Upgrades Arsenal with Six New
- RARLAB — WinRAR
Vulnerable versions: <= 7.12 (Windows only)
Fixed in: 7.13 and later - Ukrainian Government / Military (Target Ecosystem) — Windows endpoints with WinRAR, PowerShell, mshta.exe
Vulnerable versions: Windows 10; Windows 11; Windows Server 2019; Windows Server 2022
Remediation for Russian APT Gamaredon Upgrades Arsenal with Six New
Patches
- WinRAR 7.13 (released July 2025) — patches CVE-2025-8088 WinRAR path traversal vulnerability
Immediate actions
- Upgrade WinRAR to version 7.13 or later to patch CVE-2025-8088
- Block outbound DNS/HTTP to *.trycloudflare.com, *.devtunnels.ms, *.loophole.site, *.workers.dev at perimeter if not business-required
- Add confirmed C2 IPs to firewall and EDR deny lists: 64.176.173.164, 91.231.182.187, 69.67.173.214, 167.88.164.202, 172.235.166.243
- Block egress to abrargeospatial.ir, brannenburger-nagelfluh.de, pizzeria-mercy.de (compromised WordPress Kazuar C2 sites)
- Alert on outbound connections from mshta.exe, PowerShell, or wscript.exe to telegra.ph, teletype.in, rentry.co, gofile.io, write.as
Workarounds
- Disable or uninstall WinRAR if not required; use Windows built-in ZIP or a patched alternative archive tool
- Block .hta and .xhtml file execution via Windows Defender Application Control (WDAC) or AppLocker
- Restrict mshta.exe via application allowlisting if not required by business processes
- Enable Protected View for all email attachments in Microsoft Outlook
Longer-term hardening
- Deploy EDR with behavioral detection for mshta.exe executing files from Startup folder paths
- Hunt for NTFS alternate data streams in %APPDATA% and Startup directory paths
- Monitor for scheduled task creation with names DiskDiagnosticDataCollector, SilentCleanup, or SmartRetry outside Windows Update context
- Implement USB and removable media policy enforcement and LNK file scanning for files with hidden+system attributes
- Add network-based detection for multi-hop tunnel patterns and dead drop resolver callback sequences from non-browser processes
- Monitor S3-compatible cloud storage uploads (Wasabi, Tebi, Intercolo de-fra.i3storage.com) for anomalous file exfiltration
- Implement application allowlisting to restrict mshta.exe, wscript.exe, and cscript.exe execution where not required
CVEs associated with Russian APT Gamaredon Upgrades Arsenal with Six New
Weaknesses (CWE) in Russian APT Gamaredon Upgrades Arsenal with Six New
CWE-35, CWE-494
Timeline of Russian APT Gamaredon Upgrades Arsenal with Six New
- Kazuar backdoor first documented as a Turla (FSB Center 16) C# espionage implant; would later be delivered via Gamaredon initial access in 2025 collaboration
- brannenburger-nagelfluh.de (IP 217.160.0.33) first seen as a compromised WordPress site used for Turla Kazuar C2 infrastructure, later used in Gamaredon-delivered Kazuar campaigns
- abrargeospatial.ir (IP 168.119.152.19) first seen as a compromised WordPress site used for Kazuar C2, later leveraged in Gamaredon-Turla collaboration attacks
- Gamaredon observed a brief operational pause in January 2025; H1 2025 focused primarily on new tool development with lower campaign frequency than H2
- First documented Gamaredon-Turla collaboration chain: PteroGraphin delivered 3DES-encrypted Telegra.ph request leading to PteroOdd, which DLL sideloaded Kazuar v3 via vncutil64.exe and LaunchGFExperience.exe masquerading
- Second Gamaredon-Turla chain documented: PteroOdd followed by PteroEffigy fetched scrss.ps1 from eset.ydns.eu (64.176.173.164) and deployed Kazuar v2 with agent label AGN-AB-26 on high-value Ukrainian targets
- Gamaredon began using Cloudflare Workers (workers.dev) as a new C2 concealment layer, complementing existing Cloudflare Tunnels (trycloudflare.com) in use since late 2024
- Gamaredon added Microsoft devtunnels (devtunnels.ms) and Loophole (loophole.site) as C2 tunnel services; third Turla handoff chain documented via PteroPaste fetching ekrn.ps1 from 91.231.182.187 deploying Kazuar v2 with agent label AGN-AB-27
- WinRAR 7.13 released by RARLAB, patching CVE-2025-8088 path traversal vulnerability discovered by ESET researchers Cherepanov, Kosinar, and Strycek
- CVE-2025-8088 (WinRAR path traversal, CVSS 8.8 HIGH) publicly disclosed; ESET credited with discovery; affected WinRAR versions <= 7.12 on Windows via path traversal to Startup folder write
- CISA added CVE-2025-8088 to the Known Exploited Vulnerabilities catalog with remediation deadline of September 2, 2025, confirming active exploitation
- Gamaredon began active exploitation of CVE-2025-8088 in spearphishing campaigns, using weaponized XHTML with HTML smuggling to drop WinRAR archives that write HTA downloaders to the Windows Startup folder for mshta.exe execution on next login
- Intercolo (de-fra.i3storage.com) became the primary S3-compatible exfiltration endpoint for Gamaredon's PteroPSDoor and PteroVDoor tools by December 2025, following earlier use of Wasabi (early 2025) and Tebi (mid-2025)
- ESET published comprehensive white paper 'Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances' documenting all 35 spearphishing campaigns, six new Ptero tools, Turla collaboration chains, and CVE-2025-8088 exploitation
- Threadlinqs Intelligence documented Gamaredon 2025 expanded arsenal as TL-2026-0968 with full MITRE ATT&CK mapping, IOC extraction, and detection logic for defender consumption
Sources cited for Russian APT Gamaredon Upgrades Arsenal with Six New
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
- Russian APT Gamaredon Upgrades Its Arsenal, Requiring New Defenses
- Gamaredon x Turla: Two FSB Groups Collaborate to Deploy Kazuar Backdoor
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor — The Hacker News
- Gamaredon Exploits CVE-2025-8088 WinRAR to Launch Modular Spy Campaign on Ukrainian Targets — Security Affairs
- CVE-2025-8088 Detail — NIST NVD
- CISA Known Exploited Vulnerabilities Catalog — CVE-2025-8088 Entry
- Researchers Believe Gamaredon and Turla Threat Groups Are Collaborating — Help Net Security
- Google Warns of Active Exploitation of CVE-2025-8088 — The Hacker News
- ESET Malware IOC Repository — Gamaredon 2025 Indicators
- Gamaredon's PteroLNK: Dead Drop Resolvers and Evasive Infrastructure — HarfangLab
- Gamaredon in 2024 — ESET White Paper
Threats related to Russian APT Gamaredon Upgrades Arsenal with Six New
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
- Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)
- Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains
Detection coverage for TL-2026-0968
As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0968 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.