Cyber Sibling Rivalry: Gamaredon and Turla Join Forces in Ukraine’s Digital Battlefield

ESET uncovers a rare collaboration between Russia-linked groups Gamaredon and Turla. These groups teamed up in cyberattacks on Ukraine, combining tools to increase impact on critical systems during a tense geopolitical climate. The first technical link marks a new level of coordination between these two cyberespionage actors.

Pro Dashboard

Hot Take:

It looks like Russia’s cyber snoops are playing a high-stakes game of “Who Can Hack It Better?” with their new dream team, Gamaredon and Turla. Ukraine, brace yourself for a cyber tango where the malware dance partners are anything but graceful!

Key Points:

  • Russia-linked groups Gamaredon and Turla collaborated in cyberattacks on Ukraine between February and April 2025.
  • Gamaredon, known for its noisy attacks, provided access for Turla, who focused on high-value espionage targets.
  • This collaboration marks the first technical link between the two notorious cyberespionage groups.
  • Gamaredon initially breached systems, with Turla deploying the sophisticated Kazuar malware afterward.
  • ESET released IoCs and samples to help combat these cyber intrusions.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?