A Rare Convergence of Two Long-Running Espionage Operations
For more than a decade, Ukraine has been the testing ground for Russian cyber operations. Now, fresh evidence suggests two of Moscow’s most notorious hacking groups, Gamaredon and Turla, are not only working in parallel but directly collaborating to penetrate Ukrainian systems.
In a report shared this week, Slovak cybersecurity firm ESET detailed how Gamaredon’s homegrown malware tools were used earlier this year to deploy Turla’s Kazuar backdoor on multiple Ukrainian endpoints. The finding points to a notable shift in Russia’s cyber strategy: an apparent alignment of groups historically known for distinct, if sometimes overlapping, operations.
FutureCrime Summit 2026: Registrations to Open Soon for India’s Biggest Cybercrime Conference
Gamaredon, also called Armageddon, has been active since 2013, with its crude but persistent attacks frequently aimed at Ukrainian government networks. Turla, in contrast, is a more sophisticated espionage collective, known for breaching Western defence contractors and diplomatic institutions as far back as the late 1990s. Both groups are linked to Russia’s Federal Security Service, or FSB.
From PteroGraphin to Kazuar: A Coordinated Attack Chain
The sequence observed by ESET unfolded in February 2025, when Gamaredon’s PowerShell-based tool PteroGraphin launched Turla’s Kazuar backdoor. Investigators believe the tool was used to restart Kazuar v3 after a failed or incomplete installation.
By April and June, the pattern repeated. Two additional Gamaredon malware families, PteroOdd and PteroPaste, were detected installing earlier versions of Kazuar on other Ukrainian machines. Each step in the chain reflected a division of labour: Gamaredon securing entry points with lightweight downloaders, Turla embedding its far more complex surveillance implant.
Kazuar, a .NET-based backdoor first seen in 2016, is capable of exfiltrating system data, establishing persistence, and communicating with attackers through multiple channels, including web sockets and Exchange Web Services. ESET’s analysis shows the newest version contains roughly one-third more code than its predecessor, a sign of active development.
Convergence Amid Ongoing Conflict
The cooperation appears to have accelerated following Russia’s full-scale invasion of Ukraine in 2022, which has spurred both military and cyber offensives. While Gamaredon floods Ukrainian targets with spear-phishing campaigns and USB-based propagation, Turla appears to be leveraging these footholds to implant its more strategic espionage tools.
In total, seven machines were compromised by Turla-linked malware over the past 18 months, four of which were first accessed by Gamaredon. Though small in number, analysts say the incidents mark a rare tactical convergence between groups that previously operated with different targets and methods.
Whether this is an ad hoc collaboration or part of a broader Russian intelligence strategy remains uncertain. But to Ukrainian defenders and their Western partners, the implications are clear: the line between Russia’s hacking units is blurring, and the cost of underestimating their combined force could be high.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics