Earth Dahu, better known as Gamaredon, is a Russia-aligned threat actor that has continuously targeted Ukraine since at least 2013. The content describes it as one of the most active groups targeting Ukraine and tracks it under multiple aliases including Primitive Bear, Shuckworm, Aqua Blizzard, and UAC-0010. In the reported activity, Earth Dahu exploited the WinRAR path traversal vulnerability CVE-2025-8088 against Ukrainian organizations. The group used spear-phishing emails delivering malicious RAR archives, often themed as court summonses or property seizure notices, and in some cases sent from compromised government and judicial institution mailboxes. The lure archives displayed decoy documents while silently writing malicious files outside the extraction directory, including into the Windows Startup folder. Trend Micro attributed an HTA-based infection chain to Earth Dahu with high confidence. In this chain, exploitation dropped a single HTA file into Startup; after reboot or next login, mshta.exe executed the HTA, which then loaded VBScript from infrastructure using Cloudflare Workers and dynamic DNS. The content states that Earth Dahu used script-based tooling rather than compiled malware, relied on HTA, VBScript, and PowerShell, and used URLs disguised with HTTP Basic Authentication formatting so trusted domains such as ssu.gov.ua appeared as prefixes. The delivered tooling is described as espionage-focused malware or spyware modules. The content also states that this HTA-to-VBScript-to-espionage-module chain continued previously reported Earth Dahu activity and that victimology focused on Ukrainian government and military entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned espionage activity targeting Ukraine, using the same CVE-2025-8088 WinRAR exploit chain to deliver espionage tools via HTML Application files loaded through Cloudflare Workers.
Russia-aligned espionage group exploiting CVE-2025-8088 against Ukrainian targets using script-based infection chains that drop HTA files for Startup execution, then load VBScript through Cloudflare Workers and Dynamic DNS infrastructure to deliver espionage modules.
A Russia-linked espionage group persistently targeting Ukraine, using the WinRAR CVE-2025-8088 exploit to drop an HTA file into the startup folder, then leveraging mshta, Cloudflare Workers, dynamic DNS, and VBScript to deliver spyware modules.
Uses CVE-2025-8088 in spear-phishing campaigns against Ukrainian organizations to drop HTA or VBScript files into Startup, execute via mshta.exe on next login, and deliver espionage modules; reporting also notes a wiper component delivered through the same chain.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.