Trusted Services Become Gamaredon’s Covert Control Path

Gamaredon’s stealth comes from making its control traffic look like normal Windows and cloud use. That breaks the usual perimeter assumption that allowlists and simple domain blocking will expose the intrusion, because the malware can blend into services many networks already trust. Sekoia’s part 2 on GammaLoad says the chain hides inside legitimate Windows features and uses Telegram, Cloudflare, and standard cloud storage for covert C2. The report is built from decade-long telemetry and new indicators, and says every stage can be reused to push commands, change configuration, or deliver new payloads on compromised hosts. For government, defense, and critical infrastructure teams, the risk is not just one loader but a durable control path that survives basic filtering. If those outbound services are treated as ordinary, the same trust can carry espionage traffic with little local trace.

Part of the PlainSec briefing for 2026-06-03

Sources