Skip to main content
Mallory
MalwareUsed by 3 actors

GammaDrop

GammaDrop is a malware dropper associated with the Russian FSB-directed threat group BlueAlpha, which overlaps with Gamaredon, Shuckworm, Hive0051, and UNC530 and has targeted Ukrainian organizations since at least 2014. Reporting states that BlueAlpha has used GammaDrop in spearphishing-driven delivery chains, including HTML smuggling with embedded JavaScript and modified deobfuscation methods such as use of the onerror HTML event. BlueAlpha has also used Cloudflare Tunnels, specifically randomly generated TryCloudflare subdomains, to conceal GammaDrop staging infrastructure and evade traditional network detection. GammaDrop’s documented role is to write the VBScript malware GammaLoad to disk and establish persistence on the victim system. GammaLoad is described as a custom loader used since at least October 2023 for data exfiltration, credential theft, persistent access, command-and-control beaconing, and execution of additional malware. The reporting also notes BlueAlpha’s use of obfuscation techniques including junk code and random variable names, as well as DNS fast-fluxing to complicate tracking and disruption of command-and-control infrastructure. High-confidence detection-relevant details mentioned in the content include delivery via HTML attachments used for HTML smuggling, suspicious use of mshta.exe, untrusted .lnk files, requests to trycloudflare.com subdomains, and unauthorized DNS-over-HTTPS activity.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BlueAlpha

GammaDrop: acts as a dropper, writing GammaLoad to disk and ensuring persistence

via recorded future blogrecordedfuture.com
Gamaredon Group

GammaDrop: acts as a dropper, writing GammaLoad to disk and ensuring persistence

via recorded future blogrecordedfuture.com
Hive0051

GammaDrop: acts as a dropper, writing GammaLoad to disk and ensuring persistence

via recorded future blogrecordedfuture.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

"PLAYFULGHOST Delivered via Phishing and SEO Poisoning"; "Victims get infected via phishing emails"; "phishing campaign" (multiple entries)

T1566.001Spearphishing AttachmentEvidence1

BlueAlpha has been active since at least 2014 and continues to target Ukrainian organizations through relentless spearphishing campaigns to distribute custom malware.

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

BlueAlpha uses obfuscation techniques, namely extensive amounts of junk code and random variable names to complicate analysis.

T1027.006HTML SmugglingEvidence1
TacticStealth

The group delivers malware through HTML smuggling, leveraging sophisticated techniques to bypass email security systems.

T1090.002External ProxyEvidence1

BlueAlpha uses Cloudflare Tunnels to conceal its GammaDrop staging infrastructure, evading traditional network detection mechanisms.

T1105Ingress Tool TransferEvidence1

GammaDrop: acts as a dropper, writing GammaLoad to disk and ensuring persistence

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.