{"id":8669,"date":"2024-11-13T12:00:00","date_gmt":"2024-11-13T10:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=8669"},"modified":"2026-06-14T19:43:03","modified_gmt":"2026-06-14T16:43:03","slug":"eset-research-podcast-gamaredon","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2024\/11\/13\/eset-research-podcast-gamaredon\/","title":{"rendered":"ESET Research Podcast: Gamaredon"},"content":{"rendered":"<p>When describing state-backed threat actors, one would probably expect a super sophisticated, stealthy group capable of avoiding all alarms and defenses with surgical precision. With Gamaredon, most of that goes out the window as this is one noisy, extremely active Russia-aligned group that does not care if defenders uncover its activities. However, it is also an actor that develops and improves its cyberespionage tools and techniques literally every day.<\/p>\n<p>In this special episode, ESET Principal Malware Researcher <a href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/robert-lipovsky\/\">Robert Lipovsk\u00fd<\/a> plays the host \u2013 in cooperation with our usual host <a href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/aryeh-goretsky\/\">Aryeh Goretsky<\/a> \u2013 and questions ESET\u2019s house expert on Gamaredon, Senior Malware Researcher <a href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/zoltan-rusnak\/\">Zolt\u00e1n Rusn\u00e1k<\/a>. In the debate, they introduce the threat actor, including its standard modus operandi, exclusive victimology, vast collection of advanced tools and social engineering tricks, and even its estimated geolocation.<\/p>\n<p>However, these 23 minutes will cater mostly to those interested in the technical details of Gamaredon\u2019s spearphishing campaigns, techniques to weaponize Word documents and USB drives, approaches to avoid domain blocking, and increasingly advanced obfuscation. So if you\u2019re a security geek interested in this kind of threat intelligence, you\u2019re up for a treat.<\/p>\n<p>To make our podcast worth the while of defenders, Robert and Zoltan also included quite a lot of preventive measures and tips that anyone sitting in a security operations center can use to hunt for Gamaredon\u2019s activity in their network \u2013 although that mostly applies to organizations in Ukraine.<\/p>\n<p>For full details on where and how the Russia-aligned threat actor Gamaradeon operates, read more in ESET\u2019s recently published <a href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/white-papers\/cyberespionage-gamaredon-way.pdf\">white paper<\/a>. For more security research information, follow ESET Research on <a href=\"https:\/\/twitter.com\/esetresearch\">X (formerly known as Twitter)<\/a> and read our other blogposts, reports, and papers on <a href=\"https:\/\/www.welivesecurity.com\/index.html\">WeLiveSecurity.com<\/a>. If you like what you hear, subscribe for more on <a href=\"https:\/\/open.spotify.com\/show\/1WDjY2A3A3s5FKycrOVkhg\">Spotify<\/a>, <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/eset-research-podcast\/id1596306608\">Apple Podcasts<\/a>, or <a href=\"https:\/\/esetresearch.podbean.com\/\">PodBean<\/a>.<\/p>\n<\/p>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/podcasts\/eset-research-podcast-gamaredon\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ESET researchers introduce the Gamaredon APT group, detailing its typical modus operandi, unique victim profile, vast collection of tools and social engineering tactics, and even its estimated geolocation<\/p>\n","protected":false},"author":5,"featured_media":8670,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2878],"tags":[],"class_list":["post-8669","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-eset-research"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8669"}],"version-history":[{"count":1,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8669\/revisions"}],"predecessor-version":[{"id":9336,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8669\/revisions\/9336"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8670"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}