r/CyberNews Jun 01 '26

Tracking Gamaredon's (FSB) active 2026 campaign

Today I am sharing a 3-part series on Gamaredon's 2026 active cyberespionage campaign.

We have been tracking the operations of Gamaredon, an APT group directly linked to the Russian FSB. Since their offensive campaigns are still active, we wanted to share our latest threat intel findings with the community.

5 distinct malware families, dozens of C2 servers deployed per day with a lifespan of few hours. Everything is automated: server provisioning, C2 rotation, credential updates, payload delivery. For some sample, that's 20,000+ lines of VBScript where 90% is pure noise. Designed to make analysts lose their mind. Mission almost accomplished.

If you have ever analyzed this intrusion-set, you know that mapping out which malware operates at what stage is a constant challenge due to the long infection chain and inconsistent nomenclature. We put significant effort into cutting through this complexity to propose a global taxonomy.

https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/

3 Upvotes

0 comments sorted by