Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

ESET has discovered russian hacker groups Gamaredon and Turla, which are attacking Ukraine with new malware

Slovak company ESET has documented the collaboration of two well-known Russian hacking groups, Gamaredon and Turla, who jointly attacked Ukrainian organizations using the Kazuar spyware.

Leave a comment
ESET has discovered russian hacker groups Gamaredon and Turla, which are attacking Ukraine with new malware

Slovak company ESET has documented the collaboration of two well-known Russian hacking groups, Gamaredon and Turla, who jointly attacked Ukrainian organizations using the Kazuar spyware.

This is stated in the ESET report, which is cited by The Hacker News. According to the researchers, in February 2025, Gamaredon used its own tools PteroGraphin and PteroOdd to launch Kazuar on one of the computers in Ukraine. In the following months, in April and June, the same scheme was repeated - using different variants of the malware.

Gamaredon, also known as Armageddon, has been active since at least 2013 and specializes in attacks against Ukrainian government institutions. Turla is an older group that has been operating since the late 1990s and has already attacked ministries and defense companies in Europe and the United States. Both groups are linked to Russian intelligence services.

The Kazuar spyware they use allows them to collect data from an infected computer, access files, and transfer information to remote servers. Newer versions of Kazuar have become more sophisticated: they can now operate through different communication channels and bypass some protections.

Experts note that Gamaredon provides initial access to computers, while Turla deploys Kazuar for long-term espionage. This combination makes the attacks more dangerous, as one group effectively opens the "door" while the other enters with enhanced capabilities.

Recall that the activity of Russian hacker groups against Ukraine has increased significantly after the full-scale invasion in 2022. Now their attention is increasingly focused on the defense sector.

dev.ua previously reported on how the U.S. Department of Justice indicted a Ukrainian citizen who led the LockerGoga, MegaCortex, and Nefilim ransomware hacking groups. At the same time, Europol added him to its “most wanted” list.

The US has imposed sanctions on a network of North Korean hackers who pretended to be IT workers to infiltrate American companies. A Russian citizen was also targeted
The US has imposed sanctions on a network of North Korean hackers who posed as IT professionals to infiltrate American companies. A Russian citizen was also targeted
On the topic
The US has imposed sanctions on a network of North Korean hackers who posed as IT professionals to infiltrate American companies. A Russian citizen was also targeted
Hackers from the Atesh guerrilla movement attacked the largest commodity exchange in the Russian Federation, where millions of petrodollars pass through daily.
Hackers from the Atesh guerrilla movement attacked the largest commodity exchange in the Russian Federation, where millions of petrodollars pass through every day.
On the topic
Hackers from the Atesh guerrilla movement attacked the largest commodity exchange in the Russian Federation, where millions of petrodollars pass through every day.
Russian hackers suspected in large-scale hack of US federal court electronic case system
Russian hackers suspected in large-scale hack of US federal court electronic case system
On the topic
Russian hackers suspected in large-scale hack of US federal court electronic case system
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.