For the first time, the interaction between two Russian cyber espionage groups has been documented: one provides initial access to numerous systems, the other selects the most strategic targets, exploiting shared tools to hit sensitive targets in Ukraine
Milan, 22 September 2025 – The researchers of ESET, a global European leader in the cybersecurity market, have discovered the first documented cases of collaboration between Gamaredon and Turla. The two groups, both associated with Russia's Federal Security Service (FSB), have conducted joint attacks against high-profile targets in Ukraine. On the affected systems, Gamaredon installed a wide range of tools, and on one of these Turla was able to issue commands via Gamaredon payloads.
"Over the course of this year, ESET has identified Turla on seven systems in Ukraine. Since Gamaredon compromises hundreds, if not thousands of targets, this indicates that Turla focuses interest only on the most strategic ones, probably containing particularly sensitive intelligence information," explains Matthieu Faou, ESET researcher who identified the collaboration between Turla and Gamaredon together with his colleague Zoltán Rusnák.
Specifically, in February 2025, ESET Research detected Turla's Kazuar backdoor running via Gamaredon's PteroGraphin and PteroOdd malicious tools on a system in Ukraine. PteroGraphin was used to restart Kazuar v3, probably after a crash or because the backdoor had not started automatically. This indicates that PteroGraphin was employed as a recovery method by Turla. It is the first time that the two groups have been linked together through technical indicators. In April and June 2025, ESET detected that Kazuar v2 was distributed with Gamaredon's PteroOdd and PteroPaste tools.
Kazuar v3 represents the latest evolution of the Kazuar family, an advanced cyberespionage facility in C# that, according to ESET, is used exclusively by Turla and which was first detected in 2016. Other malware spread by Gamaredon include PteroLNK, PteroStew and PteroEffigy.
"Gamaredon is known for using spearphishing campaigns and malicious LNK files on removable devices, so it is likely that one of these was the entry point. We believe with reasonable certainty that the two groups – although separately linked to the FSB – are collaborating, with Gamaredon granting initial access to Turla," comments Rusnák.
Both groups report to the FSB. According to the “Ukrainian Security Service,” Gamaredon is operated by officers from the Crimea-based FSB Center 18 (also known as the “Information Security Center”), part of the FSB's counterintelligence service. Turla, however, is attributed by the British "National Cyber Security Centre" to Center 16 of the FSB, the main Russian agency for signals intelligence operations.
From an organizational perspective, it is worth highlighting that the two entities commonly associated with Turla and Gamaredon have a long history of collaboration, dating back to the Cold War era. The large-scale invasion of Ukraine in 2022 has likely strengthened this convergence, with ESET data clearly showing how the two groups' activities in recent months have focused on the Ukrainian defense sector.
Gamaredon has been active since at least 2013 and is responsible for numerous attacks, mostly targeting Ukrainian government institutions. Turla, also known as Snake, is a well-known cyber espionage group active since at least 2004, with possible origins in the late 1990s. It mainly focuses on high-profile targets, such as governments and diplomatic entities in Europe, Central Asia and the Middle East. It has compromised major organizations in the past, including the US Department of Defense in 2008 and the Swiss company RUAG in 2014.






