THREAT INTELLIGENCE REPORT

Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine

Analysis of a Russian State-Sponsored Espionage Campaign Leveraging CVE-2025-8088 and Modular Malware for Intelligence Collection Operations

Analyst
Rajkumar G
Date
02 June 2026
Classification
Public
Report Type
Threat Intelligence

Executive Summary

The Russian state-sponsored threat actor Gamaredon has been observed exploiting CVE-2025-8088, a WinRAR path traversal vulnerability, to deliver a sophisticated multi-stage malware framework targeting Ukrainian entities. The campaign employs a modular infection chain involving GammaPhish, GammaLoad, GammaWorm, and GammaSteel to facilitate persistence, credential theft, intelligence collection, and data exfiltration.

Researchers assess the activity as part of an ongoing espionage operation focused on government, military, and critical infrastructure organizations within Ukraine.

Key Intelligence Overview

Threat Actor

Gamaredon

Attribution

Russian FSB

Severity

Critical

Exploited CVE

CVE-2025-8088

Malware

GammaWorm

Target

Ukraine

Threat Actor Attribution

Gamaredon is a Russian state-sponsored cyber espionage group publicly linked to the Russian Federal Security Service (FSB). The group has maintained a long history of conducting intelligence-gathering operations against Ukrainian government agencies, military organizations, and critical infrastructure providers.

The campaign demonstrates continued investment in modular malware development and the abuse of publicly disclosed vulnerabilities to gain initial access into target environments.

Targeted Sectors

Campaign Timeline

December 2025

Ongoing development and deployment of updated malware infrastructure.

January 2026

Sekoia observes exploitation activity involving CVE-2025-8088.

Initial Infection

Victims open weaponized RAR archives containing malicious payloads.

Execution

GammaPhish launches GammaLoad downloader components.

Persistence & Collection

GammaWorm and GammaSteel establish long-term access and collect data.

Attack Chain Analysis

Initial Access

Gamaredon exploits CVE-2025-8088 in WinRAR through malicious archive files distributed to targeted victims.

Execution

GammaPhish executes an HTML Application payload that launches the GammaLoad downloader.

Persistence

GammaWorm creates scheduled tasks and deploys malicious LNK files to maintain long-term access.

Defense Evasion

The malware stores modules within NTFS Alternate Data Streams (ADS) and leverages legitimate platforms such as Telegram for command-and-control resolution.

Credential Access & Collection

GammaSteel searches for sensitive files and collects information matching predefined extensions.

Exfiltration

Collected data is transmitted to AWS S3 buckets or attacker-controlled infrastructure.

Malware Ecosystem

Malware Purpose
GammaPhish Initial HTA Payload
GammaLoad VBScript Downloader
GammaWorm Propagation & Persistence
GammaSteel Information Stealer
GammaWipe Destructive Wiper

MITRE ATT&CK Mapping

Tactic Observed Technique
Initial Access Exploitation for Client Execution
Execution VBScript
Persistence Scheduled Task
Defense Evasion NTFS Alternate Data Streams
Discovery System Information Discovery
Command & Control Dead Drop Resolver
Exfiltration Exfiltration to Cloud Storage

Indicators of Interest

Detection Opportunities

Defensive Recommendations

  1. Patch WinRAR installations immediately.
  2. Disable unnecessary script execution.
  3. Monitor USB device activity.
  4. Restrict HTA execution where possible.
  5. Implement EDR monitoring.
  6. Inspect scheduled task persistence.
  7. Monitor cloud storage exfiltration channels.
  8. Conduct threat hunting for Gamaredon TTPs.

Confidence Assessment

Confidence Level: High

Assessment is based on detailed malware analysis, observed exploitation activity, infrastructure investigation, and attribution findings published by Sekoia.

Analyst Assessment

The continued evolution of Gamaredon's malware ecosystem demonstrates the group's commitment to long-term intelligence collection operations against Ukraine. The use of modular malware, cloud infrastructure, Telegram-based dead drop resolvers, and ADS evasion techniques significantly increases operational resilience.

Organizations supporting government, defense, or critical infrastructure sectors should consider this threat highly relevant and actively monitor for associated indicators.

Intelligence Sources

References

Share Report