ESET: Gamaredon hides command traffic behind everyday web services

ESET reports that the Russia-aligned actor Gamaredon stayed focused on Ukrainian government and military targets throughout 2025. The group ran 35 spearphishing campaigns, added six new PowerShell tools, revived the PteroSetup weaponizer and upgraded its file stealers to exfiltrate data through cloud storage. Its command infrastructure was increasingly hidden behind legitimate services such as tunnels, workers, dynamic DNS, PaaS, messaging and social platforms, paste sites and dead drops.

What this means for your organisation

When command traffic travels through services your organisation already uses and trusts, domain blocking loses much of its value. The same applies to exfiltration through cloud storage: the traffic looks like normal use. The lesson transfers to Norwegian organisations even though the targets are in Ukraine, because these techniques spread quickly to other actors.

Berigo recommends

  • Define which cloud storage and tunnelling services are approved, and block the rest rather than chasing malicious domains.
  • Monitor large outbound data transfers to cloud services, including the approved ones.
  • Restrict PowerShell for ordinary users and log script execution.
  • Train key personnel on spearphishing that impersonates known counterparties.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch