GammaLoad is a custom multi-stage script-based malware component used by the Russia-linked Gamaredon threat cluster, also tracked as BlueAlpha, Shuckworm, Primitive Bear, Armageddon, and related names, in long-running cyberespionage operations primarily targeting Ukrainian government, military, and critical infrastructure organizations. It functions as a staging and loading layer within Gamaredon’s broader modular “Gamma” ecosystem, which also includes components for phishing delivery, worm-like propagation, information theft, and destructive activity.
GammaLoad has been observed as a VBScript-based loader operating in a cascading multi-stage chain. Its role is to fingerprint infected hosts, update network or configuration data stored locally, beacon to command-and-control infrastructure, and retrieve and execute additional arbitrary VBScript or other follow-on payloads. Reported downstream payloads include GammaWorm for propagation and persistence and GammaSteel for information theft. Some reporting also describes GammaLoad itself as enabling credential theft, data exfiltration, and persistent access, reflecting its role as both a loader and an operational access mechanism in Gamaredon intrusions.
Observed delivery chains place GammaLoad after initial access via spearphishing and HTML smuggling. In more recent campaigns, weaponized XHTML lures and booby-trapped archives exploiting CVE-2025-8088 in WinRAR were used to launch an HTA stage that retrieved GammaLoad. Earlier activity also used spearphishing messages with self-extracting archives and script-based execution through native Windows utilities. Associated operations make extensive use of legitimate services and dead-drop resolver techniques to conceal infrastructure and blend malicious traffic with normal activity, including cloud storage, tunneling services, and public web or messaging platforms.
GammaLoad targets Windows environments and is notable for Gamaredon’s emphasis on modularity, rapid iteration, obfuscation, and resilient access. In the broader intrusion set, surviving components can often fetch fresh payloads and restore functionality, complicating remediation. GammaLoad is therefore best understood as a central staging loader in a mature espionage framework rather than a standalone commodity malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to Sekoia, the attack consists of exploiting the bug CVE-2025-8088, a path traversal bug in WinRAR, to run an HTML App payload called GammaPhish, which is later used to get a VBScript payload from the C2 server.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon used GammaPhish, GammaWorm, GammaLoad, and GammaSteel to establish persistence, achieve physical propagation, and steal documents, actively exploiting legitimate Services, cloud storage, and tunneling infrastructure.
Since at least October 2023 BlueAlpha has delivered the custom VBScript malware GammaLoad, enabling data exfiltration, credential theft, and persistent access to compromised networks.
Since at least October 2023 BlueAlpha has delivered the custom VBScript malware GammaLoad, enabling data exfiltration, credential theft, and persistent access to compromised networks.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers started with spear-phishing messages using a self-extracting 7-zip file, which was downloaded via the system’s default browser.
Historically, according to the 2015 LookingGlass report Operation Armageddon: Cyber Espionage as a Strategic Component of Russian Modern Warfare, Gamaredon conducted spearphishing campaigns using stolen, highly relevant decoy documents of mimicking Ukrainian institutions to target government entities.
resulting in the execution of arbitrary code retrieved from a command-and-control (C2) server
Following the downloading of the XML file onto victim networks, the attackers executed a PowerShell stealer.
We recovered multiple VBScript loaders from the compromised hosts. It seems that these loaders operate in a continuous cascade, with four distinct execution stages observed during our analysis.
BlueAlpha uses obfuscation techniques, namely extensive amounts of junk code and random variable names to complicate analysis.
GammaLoad: a custom loader capable of beaconing to its C2 and executing additional malware
Their primary objectives are to fingerprint the host system, update the network configuration in the registry using Dead Drop Resolvers (DDRs), fetch and execute arbitrary VBScript payloads from the C2 servers.
Their primary objectives are to fingerprint the host system, update the network configuration in the registry using Dead Drop Resolvers (DDRs), fetch and execute arbitrary VBScript payloads from the C2 servers.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used by Gamaredon as part of operations focused on persistence, propagation, and document theft.
Intermediate staging layer composed of VBScript loaders that fingerprint the host, update network configuration in the registry using dead drop resolvers, and fetch and execute arbitrary VBScript payloads from C2 servers.
A loader in the infection chain that is likely deployed by GammaPhish and used to deliver other Gamaredon malware families such as GammaSteel, and possibly GammaWorm or GammaWipe.
An intermediate VBScript downloader in the Gamaredon infection chain that fingerprints the host, updates network configuration in the registry using dead drop resolvers, and fetches and executes arbitrary VBScript payloads from C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.