Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
2026-06-26T08:51:37Z•a0864ba7652478079277a9ab659b58c954342ec7b926b832a8d4020f466447a5
APTAmadeyAndroid RATBTMOBEDR-killersESETEvilTokensFishMongerFrostyNeighborGamaredonGentlemen (RaaS)GopherWhisperOperation EndgameScarCruftSprySOCKSStealcWeLiveSecurityWebwormbotnetinfostealerkernel-driver-malwarephishingsupply-chain-attackthreat-intelligencetoken-based-auth-bypass
What happened
ESET WeLiveSecurity June 2026 roundup highlighting active APT and criminal tool development: Gamaredon (2025–2026) is increasingly using legitimate online services (tunnels, workers, dead drops) to hide C2 and exfiltrate data; coordinated takedown support (Operation Endgame) disrupted the Amadey botnet and Stealc infostealer; the RaaS group ‘Gentlemen’ maintains and expands EDR-killer frameworks that abuse vulnerable drivers; FishMonger deployed a new Windows backdoor (SprySOCKS) that weaponizes a kernel driver for stealth; EvilTokens phishing kit subverts Microsoft authentication flows to hij
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- a0864ba7652478079277a9ab659b58c954342ec7b926b832a8d4020f466447a5
- Enrichment time
- 2026-06-26T08:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.