← All news

general

Gamaredon Sharpens Its Toolkit Against Ukrainian Targets

2026-06-27

Gamaredon, the FSB-linked group that has been battering Ukrainian targets since well before the full-scale invasion, has quietly raised its game. Researchers tracking the crew say the malware loaders are harder to spot, the infrastructure is better hidden, and the operators are running with more discipline than the spray-and-pray reputation they earned in earlier years.

For a long time Gamaredon has been treated as the workhorse of Russian cyber operations against Ukraine. High volume, broad targeting, and a willingness to keep poking at the same victims until something gives. The shift is in the polish rather than the ambition.

What has actually changed

Newer loaders chain together more stages before anything obviously malicious lands on disk. They lean harder on legitimate cloud and messaging services to disguise their traffic as ordinary noise. Command-and-control servers rotate fast enough to make static blocklists feel like they were written for a different decade.

  • Multi-stage loaders that fragment behaviour and delay anything worth detecting.
  • Living off trusted services so outbound traffic looks unremarkable.
  • Rapid infrastructure churn that frustrates indicator-based defences.

What hasn't changed

The initial access route. Gamaredon still relies on spear-phishing with weaponised documents, frequently sent from compromised accounts inside organisations the target already deals with. The lures are written in fluent Ukrainian, reference real bureaucratic detail, and turn up from someone the recipient has corresponded with before.

That is the part defenders keep returning to. All the loader cleverness in the world only matters once someone has opened the attachment. The technical stack on the back end can be as polished as you like, the operation still depends on a person making a quick judgement call on a Tuesday morning about whether a document from a familiar name is worth a click.

Why this matters outside Ukraine

For anyone watching from the rest of the world, the useful detail is the shape of the tradecraft, not the specific indicators. State-aligned crews are converging on the same playbook: a trusted-looking sender, a plausible document, a layered loader, and infrastructure that moves faster than your block list. The technical signatures will keep changing. The pattern won't.

Endpoint tooling absolutely helps, particularly against the later stages where the loader finally drops something it wants to run. But the cheapest, most consistent win sits earlier in the chain. People who notice that a familiar contact is asking something slightly out of character, who hover over a link before clicking, who pause for a beat when a document wants macros enabled. That instinct is built, not bought.

Gamaredon will keep iterating. The crews learning from them will, too. The organisations that fare best are the ones treating the inbox as a piece of critical infrastructure rather than a productivity tool that occasionally goes wrong.

Gamaredon Sharpens Its Toolkit Against Ukrainian Targets | RiskSense