Gamaredon and Turla collaboration to deploy Kazuar Backdoor in Ukraine
Summary
Hide β²
Show βΌ
Gamaredon and Turla, two Russian cyber espionage groups, have been collaborating to target Ukrainian entities. The groups used Gamaredon's tools to deploy Turla's Kazuar backdoor on multiple Ukrainian machines. This collaboration began in February 2025 and continued through June 2025, with a focus on the Ukrainian defense sector. The attack involved Gamaredon's tools PteroGraphin, PteroOdd, and PteroPaste to deliver the Kazuar backdoor. The collaboration indicates a coordinated effort to gain access to specific machines in Ukraine and deliver the Kazuar backdoor. Gamaredon and Turla are both affiliated with the Russian Federal Security Service (FSB). The collaboration is likely fueled by Russia's full-scale invasion of Ukraine in 2022.
Timeline
-
19.09.2025 11:24 π° 1 articles Β· β± 10h ago
Gamaredon and Turla collaboration to deploy Kazuar Backdoor in Ukraine
In February 2025, Gamaredon and Turla began collaborating to target Ukrainian entities. The groups used Gamaredon's tools to deploy Turla's Kazuar backdoor on multiple Ukrainian machines. The attacks continued through June 2025, with a focus on the Ukrainian defense sector. The collaboration is likely fueled by Russia's full-scale invasion of Ukraine in 2022. The attacks involved the use of PteroGraphin, PteroOdd, and PteroPaste to deliver the Kazuar backdoor. Kazuar v2 and v3 share the same codebase, with v3 introducing additional network transport methods.
Show sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
Information Snippets
-
Gamaredon and Turla, both affiliated with the Russian FSB, have been collaborating to target Ukrainian entities.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
The collaboration involved using Gamaredon's tools to deploy Turla's Kazuar backdoor on Ukrainian machines.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
The attacks began in February 2025 and continued through June 2025.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
The attacks primarily targeted the Ukrainian defense sector.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
Gamaredon's tools used in the attacks include PteroGraphin, PteroOdd, and PteroPaste.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
PteroGraphin was used to restart the Kazuar v3 backdoor, possibly after it crashed or was not launched automatically.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
Kazuar v2 and v3 share the same codebase, with v3 introducing additional network transport methods.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
The attack chain involved downloading a PowerShell downloader that retrieved a payload from Telegraph to execute Kazuar.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24
-
The collaboration is likely fueled by Russia's full-scale invasion of Ukraine in 2022.
First reported: 19.09.2025 11:24π° 1 source, 1 articleShow sources
- Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine β thehackernews.com β 19.09.2025 11:24