# Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

DevFeed: [Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances](<https://devfeed.tech/articles/gamaredon-in-2025-leveraging-tunnels-workers-dead-drops-and-new-alliances-8371.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/>)

Author: Zoltán Rusnák

Published: 2026-06-25T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [dns](<https://devfeed.tech/tags/dns.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [storage](<https://devfeed.tech/tags/storage.md>)

## AI overview

ESET Research analyzes Gamaredon's 2025 cyberespionage activity against Ukrainian governmental and military institutions, including spearphishing, new malicious PowerShell tools, cloud-based data exfiltration, and concealed C&C infrastructure.

## Source excerpt

ESET Research analyzes Gamaredon's new toolset and the group's growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data