Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

2026-06-26T08:51:37Za0864ba7652478079277a9ab659b58c954342ec7b926b832a8d4020f466447a5
APTAmadeyAndroid RATBTMOBEDR-killersESETEvilTokensFishMongerFrostyNeighborGamaredonGentlemen (RaaS)GopherWhisperOperation EndgameScarCruftSprySOCKSStealcWeLiveSecurityWebwormbotnetinfostealerkernel-driver-malwarephishingsupply-chain-attackthreat-intelligencetoken-based-auth-bypass

What happened

ESET WeLiveSecurity June 2026 roundup highlighting active APT and criminal tool development: Gamaredon (2025–2026) is increasingly using legitimate online services (tunnels, workers, dead drops) to hide C2 and exfiltrate data; coordinated takedown support (Operation Endgame) disrupted the Amadey botnet and Stealc infostealer; the RaaS group ‘Gentlemen’ maintains and expands EDR-killer frameworks that abuse vulnerable drivers; FishMonger deployed a new Windows backdoor (SprySOCKS) that weaponizes a kernel driver for stealth; EvilTokens phishing kit subverts Microsoft authentication flows to hij

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
a0864ba7652478079277a9ab659b58c954342ec7b926b832a8d4020f466447a5
Enrichment time
2026-06-26T08:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances · Baitaphish