← Back to BrewedIntel
adversaryhighAPTCyber EspionageGamaredonTurla

Sep 19, 2025 • ESET WeLiveSecurity

Gamaredon X Turla collab

This report highlights a significant collaboration between two notorious Advanced Persistent Threat (APT) groups, Turla and Gamaredon. Both entities are...

Source
ESET WeLiveSecurity
Category
adversary
Severity
high

Executive Summary

This report highlights a significant collaboration between two notorious Advanced Persistent Threat (APT) groups, Turla and Gamaredon. Both entities are assessed as being associated with the Russian Federal Security Service (FSB). The joint operation specifically targets high-profile entities within Ukraine, indicating a coordinated cyber espionage or sabotage campaign. This alliance suggests a potential escalation in threat capabilities, combining Turla's sophistication with Gamaredon's regional focus. The primary impact involves the compromise of critical infrastructure or government systems, posing severe risks to national security and data integrity. While specific malware families were not detailed in this brief, organizations should anticipate sophisticated intrusion techniques. Mitigation strategies must focus on enhanced network monitoring, strict access controls, and threat intelligence sharing regarding FSB-associated TTPs. Immediate vigilance is required for Ukrainian stakeholders and allied nations supporting them against this converged threat landscape.

Summary

Notorious APT group Turla collaborates with Gamaredon, both FSB-associated groups, to compromise high‑profile targets in Ukraine

Published Analysis

This report highlights a significant collaboration between two notorious Advanced Persistent Threat (APT) groups, Turla and Gamaredon. Both entities are assessed as being associated with the Russian Federal Security Service (FSB). The joint operation specifically targets high-profile entities within Ukraine, indicating a coordinated cyber espionage or sabotage campaign. This alliance suggests a potential escalation in threat capabilities, combining Turla's sophistication with Gamaredon's regional focus. The primary impact involves the compromise of critical infrastructure or government systems, posing severe risks to national security and data integrity. While specific malware families were not detailed in this brief, organizations should anticipate sophisticated intrusion techniques. Mitigation strategies must focus on enhanced network monitoring, strict access controls, and threat intelligence sharing regarding FSB-associated TTPs. Immediate vigilance is required for Ukrainian stakeholders and allied nations supporting them against this converged threat landscape. Notorious APT group Turla collaborates with Gamaredon, both FSB-associated groups, to compromise high‑profile targets in Ukraine Notorious APT group Turla collaborates with Gamaredon, both FSB-associated groups, to compromise high‑profile targets in Ukraine

Linked Entities

  • Gamaredon
  • Turla