216.73.217.22

Gamaredon X Turla collaboration

· Published 27/09/2025 04:01 · Modified 29/09/2025 09:22

Export JSON

Essential information

Published
27/09/2025 04:01
Modified
29/09/2025 09:22
Tags
2025-09-19 2025-09-27 apt backdoor collaboration cyberespionage fsb kazuar pteroeffigy pterographin pterolnk pteroodd pteropaste pterostew russia ukraine
Related entities
1 intrusion sets (apt), 6 malware, 3 others

Description

ESET Research has uncovered between notorious groups Gamaredon and Turla, both associated with 's , targeting high-profile victims in . The research reveals Gamaredon tools being used to restart and deploy Turla's on compromised machines. This marks the first known instance of cooperation between these groups, with Turla selectively choosing valuable targets from Gamaredon's numerous compromises. The involves the use of various Gamaredon tools like , , and to facilitate Turla's operations. The report details multiple attack chains, including the restart of v3 and deployment of v2, demonstrating a sophisticated level of coordination between the two threat actors.

External references