Cybersecurity researchers have uncovered compelling evidence of unprecedented cooperation between two Russian state-sponsored hacking groups, Gamaredon and Turla, in coordinated attacks against Ukrainian targets.
## The Collaboration Revealed
Slovak cybersecurity firm ESET discovered that Gamaredon’s malware tools—PteroGraphin and PteroOdd—were being used to deploy Turla’s sophisticated Kazuar backdoor on Ukrainian systems. This marks the first documented case of these two FSB-affiliated groups working together operationally.
“PteroGraphin was used to restart the Kazuar v3 backdoor, possibly after it crashed or was not launched automatically,” ESET researchers explained. “This suggests Turla is using Gamaredon’s tools as a recovery method.”
## The Players Behind the Attacks
**Gamaredon** (also known as Aqua Blizzard) has been active since 2013, primarily targeting Ukrainian government institutions. The group specializes in initial access and persistence mechanisms.
**Turla** (also called Secret Blizzard or Snake) is a more sophisticated espionage group operating since at least 2004. Known for high-profile breaches including the US Department of Defense (2008) and Swiss defense company RUAG (2014), Turla focuses on government and diplomatic targets across Europe, Central Asia, and the Middle East.
Both groups are assessed to be affiliated with Russia’s Federal Security Service (FSB).
## Attack Methods and Timeline
The collaboration intensified following Russia’s 2022 invasion of Ukraine, with attacks primarily targeting Ukraine’s defense sector. ESET identified three distinct attack chains:
**February 2025**: Gamaredon deployed PteroGraphin to execute Turla’s latest Kazuar v3 backdoor, which includes enhanced features like web socket communications and Exchange Web Services integration.
**April-June 2025**: Additional attacks used PteroOdd and PteroPaste tools to deliver Kazuar v2, demonstrating the sustained nature of this partnership.
## Technical Sophistication
The attacks reveal a strategic division of labor: Gamaredon handles initial access through spear-phishing and malicious files, while Turla provides advanced backdoor capabilities. The Kazuar malware can harvest extensive system information and maintain persistent access to compromised networks.
Notably, Gamaredon’s tools gather .NET framework information—data that would be valuable to Turla since their Kazuar backdoor is .NET-based, while Gamaredon’s own arsenal lacks .NET malware.
## Broader Implications
ESET detected Turla-related indicators on seven Ukrainian machines over 18 months, with four compromised by Gamaredon in January 2025 alone. This collaboration represents a significant escalation in Russian cyber operations against Ukraine, combining Gamaredon’s access capabilities with Turla’s advanced espionage tools.
“We now believe with high confidence that both groups are cooperating and that Gamaredon is providing initial access to Turla,” ESET researchers concluded, highlighting how Russia’s cyber warfare strategy continues to evolve and intensify.
