Analysis of a Russian State-Sponsored Espionage Campaign Leveraging CVE-2025-8088 and Modular Malware for Intelligence Collection Operations
The Russian state-sponsored threat actor Gamaredon has been observed exploiting CVE-2025-8088, a WinRAR path traversal vulnerability, to deliver a sophisticated multi-stage malware framework targeting Ukrainian entities. The campaign employs a modular infection chain involving GammaPhish, GammaLoad, GammaWorm, and GammaSteel to facilitate persistence, credential theft, intelligence collection, and data exfiltration.
Researchers assess the activity as part of an ongoing espionage operation focused on government, military, and critical infrastructure organizations within Ukraine.
Gamaredon
Russian FSB
Critical
CVE-2025-8088
GammaWorm
Ukraine
Gamaredon is a Russian state-sponsored cyber espionage group publicly linked to the Russian Federal Security Service (FSB). The group has maintained a long history of conducting intelligence-gathering operations against Ukrainian government agencies, military organizations, and critical infrastructure providers.
The campaign demonstrates continued investment in modular malware development and the abuse of publicly disclosed vulnerabilities to gain initial access into target environments.
Ongoing development and deployment of updated malware infrastructure.
Sekoia observes exploitation activity involving CVE-2025-8088.
Victims open weaponized RAR archives containing malicious payloads.
GammaPhish launches GammaLoad downloader components.
GammaWorm and GammaSteel establish long-term access and collect data.
Gamaredon exploits CVE-2025-8088 in WinRAR through malicious archive files distributed to targeted victims.
GammaPhish executes an HTML Application payload that launches the GammaLoad downloader.
GammaWorm creates scheduled tasks and deploys malicious LNK files to maintain long-term access.
The malware stores modules within NTFS Alternate Data Streams (ADS) and leverages legitimate platforms such as Telegram for command-and-control resolution.
GammaSteel searches for sensitive files and collects information matching predefined extensions.
Collected data is transmitted to AWS S3 buckets or attacker-controlled infrastructure.
| Malware | Purpose |
|---|---|
| GammaPhish | Initial HTA Payload |
| GammaLoad | VBScript Downloader |
| GammaWorm | Propagation & Persistence |
| GammaSteel | Information Stealer |
| GammaWipe | Destructive Wiper |
| Tactic | Observed Technique |
|---|---|
| Initial Access | Exploitation for Client Execution |
| Execution | VBScript |
| Persistence | Scheduled Task |
| Defense Evasion | NTFS Alternate Data Streams |
| Discovery | System Information Discovery |
| Command & Control | Dead Drop Resolver |
| Exfiltration | Exfiltration to Cloud Storage |
Confidence Level: High
Assessment is based on detailed malware analysis, observed exploitation activity, infrastructure investigation, and attribution findings published by Sekoia.
The continued evolution of Gamaredon's malware ecosystem demonstrates the group's commitment to long-term intelligence collection operations against Ukraine. The use of modular malware, cloud infrastructure, Telegram-based dead drop resolvers, and ADS evasion techniques significantly increases operational resilience.
Organizations supporting government, defense, or critical infrastructure sectors should consider this threat highly relevant and actively monitor for associated indicators.