Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions

Turla malware was deployed in February on select systems that Gamaredon had compromised in January.

Russia attack on Ukraine

Two Russian state-sponsored threat actors have been working together in recent cyberattacks against Ukrainian targets, evidence collected by ESET suggests.

Specifically, the company found that, between February and April 2025, tools that Gamaredon had deployed were used to restart and deploy Turla malware on the systems of select victims in Ukraine.

Turla, also known as Krypton, Snake, Venomous Bear, and Waterbug, has been active since at least 2004, focusing on high-profile targets, including diplomats and government entities in Europe, Central Asia, and the Middle East.

Gamaredon, also known as Armageddon, BlueAlpha, Blue Otso, Callisto, Iron Tilden, Primitive Bear, Sector C08, and Winterflounder, has been active since at least 2013, mainly targeting individuals and organizations in Ukraine.

Gamaredon is believed to have conducted thousands of intrusions against Ukrainian entities. This year, on four of the compromised machines, ESET discovered that the APT’s tools were used to issue commands to and deploy Turla implants.

In February 2025, Gamaredon’s PteroGraphin tool was used as a recovery method to restart Turla’s Kazuar espionage implant, likely after it crashed, ESET says. In April, Gamaredon’s PteroOdd and PteroPaste were used to deploy Kazuar v2 installers.

Advertisement. Scroll to continue reading.

“It is worth noting that, prior to this, the last time we detected a Turla compromise in Ukraine was in February 2024. All those elements, and the fact that Gamaredon is compromising hundreds if not thousands of machines, suggest that Turla is interested only in specific machines, probably ones containing highly sensitive intelligence,” ESET notes.

The cybersecurity firm assesses with strong confidence that the two state-sponsored groups are working together: it is unlikely that Turla has reproduced Gamaredon’s infection chain to abuse its tools, or that Gamaredon has access to Kazuar.

Additionally, ESET points out, both operations are run by officers of the Russian intelligence service FSB, albeit Gamaredon is associated with Center 18 (the Center for Information Security in Crimea) and Turla with Center 16 (Russia’s main signals intelligence agency).

“From an organizational perspective, it is worth noting that the two entities commonly associated with Turla and Gamaredon have a long history of reported collaboration, which can be traced back to the Cold War era,” ESET notes.

Related: US Offers $10 Million for Three Russian Energy Firm Hackers

Related: Amazon Disrupts Russian Hacking Campaign Targeting Microsoft Users

Related: US Sanctions Russian National, Chinese Firm Aiding North Korean IT Workers

Related: Russian APT Exploiting 7-Year-Old Cisco Vulnerability: FBI

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.