In 2024, the pro-Russian APT group targeted exclusively Ukrainian institutions with intensified spearphishing campaigns, introducing new tools for evasion and persistence, and hiding C&C infrastructure behind Cloudflare tunnels and third-party services
ESET, a global European leader in the cybersecurity market, has published a white paper that analyzes the evolution of the APT Gamaredon group's equipment, the new techniques aimed at concealment and the increasingly aggressive spearphishing campaigns conducted over the course of the year.
Gamaredon is an APT group attributed by the Security Service of Ukraine (SSU) to the 18th Center of Information Security of the Russian Federal Security Service (FSB). It has been active since at least 2013 and has been systematically targeting Ukrainian government institutions ever since. In 2024, the group's activities were focused exclusively on targets in Ukraine. According to ESET's latest analysis, the group is still extremely active: it continues to attack the country, but has significantly updated its tactics and tools in the meantime. Its main objective remains cyber espionage in support of Russian geopolitical interests.
Over the past year, Gamaredon significantly increased the scope and frequency of its spearphishing campaigns by adopting new delivery methods. In at least one case, one of the payloads used was used solely to spread Russian propaganda content.
Spearphishing activities intensified especially in the second half of 2024. The campaigns generally lasted from one to five consecutive days and involved sending emails containing malicious archives (RAR, ZIP, 7z) or XHTML files that exploited HTML smuggling techniques. These files distributed malicious HTAs or LNKs, designed to execute embedded VBScript downloaders, such as PteroSand. In October 2024, ESET detected an anomaly compared to the group's usual tactics: the spearphishing emails contained malicious links instead of traditional attachments. Another novelty that emerged in the same period is the use of LNK files to execute PowerShell commands directly from domains generated via Cloudflare, with the aim of evading traditional detection systems.
The group's toolset has undergone significant updates. While few new tools have been introduced, Gamaredon has devoted significant resources to improving existing ones. The new tools are designed to provide greater stealth, persistence and lateral movement capabilities. Tools already in use have been enhanced with more sophisticated obfuscation techniques, advanced evasion strategies, and more effective methods for lateral movement and data exfiltration.
"A particularly interesting discovery dates back to July 2024, when we detected an ad hoc VBScript payload distributed by the group's downloaders. It had no espionage functionality: its sole purpose was to automatically open a Telegram channel called Guardians of Odessa, used to spread pro-Russian propaganda aimed at the Odessa region," explains Zoltán Rusnák, an ESET researcher who monitors Gamaredon's activities.
Throughout 2024, the group continued to invest energy in circumventing network defenses. Although to a lesser extent than in the past, it continued to use fast-flux DNS techniques, with frequent rotation of the IP addresses associated with its domains. Additionally, it has increasingly relied on third-party services such as Telegram, Telegraph, Codeberg, Dropbox, and Cloudflare tunnels to dynamically hide and deploy its C&C infrastructure.
"Despite relatively limited technical resources and the abandonment of older tools, Gamaredon continues to pose a significant threat thanks to constant innovation, aggressive spearphishing campaigns and determination to evade detection mechanisms. As long as Russia's war against Ukraine continues, it is foreseeable that the group will continue to refine its tactics and intensify its cyberespionage operations against Ukrainian institutions," concludes Rusnák.






