news.mlab.sh
Back to the feed
threat-intel

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

High
Summary

The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistence, leveraging Telegram for command and control, and exfiltrating data to AWS S3. The sophisticated nature of the attack highlights Gamaredon's resilience and adaptability.

Gamaredon, a Russian state-sponsored group linked to the FSB, has been actively exploiting a path traversal flaw in WinRAR (CVE-2025-8088) to deliver a complex malware payload to targets within Ukraine. The initial stage involves deploying GammaPhish, an HTML Application payload, which then downloads GammaLoad, a Visual Basic Script (VBScript) downloader. GammaLoad subsequently executes GammaWorm, a worm designed for persistence through scheduled tasks and hiding malicious files. GammaWorm utilizes Telegram for command and control and employs NTFS Alternate Data Streams (ADS) to conceal its core modules.

Alongside GammaWorm, the campaign utilizes GammaSteel, a modular information stealer that captures files with specific extensions and exfiltrates them to AWS S3 or an attacker-controlled server. Sekoia notes the infection chain's adaptability and potential for distributing other malware families, including GammaWipe (GamaWiper). The deployment vector of GammaWorm remains ambiguous, potentially delivered concurrently with GammaLoad or independently via user-executed USB drives. This activity is part of a broader trend of targeting Ukrainian government, military, and critical infrastructure entities via spear-phishing.

Related threat activity includes UAC-0184 and UAC-0247, both targeting Ukrainian military and drone operators, respectively, and the ongoing activity of PixyNetLoader, attributed to APT28, exploiting a Microsoft Office vulnerability (CVE-2026-21509). These overlapping campaigns demonstrate the sophistication and persistence of the threat landscape.

Read the full article at The Hacker News