As cited
Copy frozen at (site build).
threat intel
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
ESET Research examined Gamaredon's evolved tactics in 2025, noting the group's increased use of legitimate online services to conceal command and control infrastructure and exfiltrate data. The analysis documents new toolset capabilities and the threat actor's reliance on tunneling, workers, dead drops, and emerging partnerships.
Why it matters: Organizations tracked by Gamaredon need to monitor for abuse of legitimate services in network traffic and implement data exfiltration controls; defenders should review ESET's findings on the group's new tooling to improve detection.
- Source published
- First seen by Cybersecurity Tracker