Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatcritical-infrastructure-threatphishing-campaign-intelligence

Gamaredon Exploits WinRAR Flaw to Deploy Modular Gamma Malware in Ukraine

Updated 14h agoFirst seen May 25, 202613 sources

Researchers attributed a January 2026 cyberespionage campaign against Ukrainian government, military, and critical infrastructure organizations to the Russia-linked Gamaredon group, which used booby-trapped spearphishing attachments and malicious RAR archives exploiting WinRAR path traversal flaw CVE-2025-8088 for initial access. The infection chain dropped an HTA payload dubbed GammaPhish, which launched via mshta.exe and fetched follow-on VBScript components including GammaLoad, GammaWorm, and GammaSteel. Sekoia said the operation marks a shift from Gamaredon’s older Pteranodon tooling to a fragmented, modular ecosystem in which multiple stages can independently act as backdoors and retrieve arbitrary remote code.

The malware emphasized stealth, persistence, and resilient command-and-control. GammaWorm established persistence through scheduled tasks and RunOnce registry keys, hid modules in NTFS Alternate Data Streams, and spread through USB devices and network shares using malicious LNK shortcuts, including into air-gapped environments. Command-and-control discovery relied on dead-drop resolvers hosted on Telegram, Telegra.ph, graph.org, Teletype, Cloudflare Workers, and operator infrastructure, while GammaSteel staged dozens of DPAPI-encrypted modules in the registry and exfiltrated selected files to AWS S3 or other S3-compatible storage with fallback to attacker-controlled servers. Because fresh payloads can be fetched at multiple stages, researchers warned that confirmed compromises may require full system wiping.

Share:
Gamaredon Exploits WinRAR Flaw to Deploy Modular Gamma Malware in Ukraine
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 9, 202621d ago

Trend Micro links Shadow-Earth-066 and Gamaredon to WinRAR exploitation

Trend Micro reported that at least two Russia-aligned clusters, Shadow-Earth-066 and Earth Dahu (Gamaredon), exploited WinRAR path traversal flaw CVE-2025-8088 in email attacks against Ukrainian military and government organizations. The report said Shadow-Earth-066 used the flaw to deploy an updated GiftedCrook stealer, while Gamaredon used HTA and VBScript stages to deliver espionage modules.

Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Jun 2, 202627d ago

Gamaredon launches January 2026 campaign exploiting WinRAR flaw

Sekoia analyzed a January 2026 Gamaredon intrusion chain targeting Ukrainian government, military, and critical infrastructure entities. The campaign used weaponized xHTML files and a malicious RAR archive exploiting WinRAR path traversal vulnerability CVE-2025-8088 for initial access.

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Gurucul publishes threat notice with Gamaredon IOCs

Gurucul published a high-severity threat notice summarizing the Gamaredon activity and providing indicators of compromise, including URLs, an IP address, MD5 hashes, and detection queries. The notice cited Sekoia's reporting as its source.

FSB’s Matryoshka #1/3 - Gamaredon’s Gifts That Keep Unpacking - GammaPhish and GammaWorm | Community Portal | Gurucul
Jun 1, 202629d ago

Sekoia publishes Gamaredon 'Gamma' malware analysis

On June 1, 2026, Sekoia published a report reconstructing the modular espionage chain and introducing the GammaPhish, GammaLoad, GammaWorm, GammaSteel, and GammaWipe taxonomy. The report said Gamaredon had shifted away from its historical Pteranodon framework toward a fragmented ecosystem in which multiple stages can independently act as backdoors and fetch remote code.

FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations
Jul 1, 20251y ago

WinRAR patches CVE-2025-8088 in version 7.13

WinRAR fixed the path traversal vulnerability CVE-2025-8088 in version 7.13 in July 2025. The flaw allowed attackers to write files outside the extraction directory via NTFS Alternate Data Streams, including into the Windows Startup folder for execution at next login.

Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088
Feb 23, 20215y ago

Talos documents Gamaredon activity

Cisco Talos published reporting on Gamaredon activity, providing historical context on the threat actor referenced by later coverage.

Gamaredon - When nation states don’t pay all the bills
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

77 LINKEDOpen in app
Affected products
15 linked
WinrarKeepassTelegramWindowsCloudflareAmazon Simple Storage ServicePowershellOpera BrowserFirefoxOpenvpnOperaSystem Center Configuration ManagerChromeWindows Server Update ServicesMicrosoft Office
Organizations
32 linked
WinRARKeepassTrend MicroMozillaCheck Point Software TechnologiesPassMark SoftwareAmazon Web ServicesPalo Alto NetworksEsetInternational Business MachinesCloudflareSekoiaRecorded FutureHarfangLabDark ReadingSupabaseBritish Broadcasting CorporationPayPalMicrosoft CorporationOperaTelegramCyber Security NewsDeutsche WelleClearSkySecurityOnline.infoHetznerGoogleSecurity AffairsExaTrackSecure.comGuruculBaxetGroup Inc.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.