GammaLoad is a multi-stage VBScript downloader and staging component used by the Russia-linked Gamaredon group, also tracked as Armageddon, Shuckworm, UAC-0010, and BlueAlpha. It operates as a cascading four-stage loader that fingerprints Windows hosts, maintains registry-based configuration, resolves active command-and-control infrastructure through dead-drop resolvers, and retrieves and executes follow-on VBScript or other payloads. GammaLoad has been used to deploy components including GammaWorm, a propagation and persistence tool, and GammaSteel, an information stealer. It supports persistent access, credential theft, and data exfiltration through the broader Gamaredon malware chain. Campaigns have delivered GammaLoad through spearphishing lures, including weaponized document and HTML-based attachments, and have targeted Ukrainian government, military, and critical-infrastructure organizations. More recent operations used a WinRAR path-traversal vulnerability to establish execution at user logon before retrieving GammaLoad.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Gamaredon and UAC-0226 are actively exploiting CVE-2025-8088, a CVSS 8.8 WinRAR path traversal flaw, to place malicious payloads outside the intended RAR extraction directory, including in the Windows Startup folder.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GammaLoad operates as a cascading four-stage VBScript downloader. It fingerprints the host, resolves live C2 addresses by parsing Telegram and Cloudflare-hosted Dead Drop Resolver pages, stores configuration in the Windows registry, and fetches final payloads.
Since at least October 2023 BlueAlpha has delivered the custom VBScript malware GammaLoad, enabling data exfiltration, credential theft, and persistent access to compromised networks.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Grabs the IP address associated with the configured C2 domain using WMI WMI query format: SELECT * FROM Win32_PingStatus WHERE Address={configured_c2_domain}
resulting in the execution of arbitrary code retrieved from a command-and-control (C2) server
Following the downloading of the XML file onto victim networks, the attackers executed a PowerShell stealer.
The macro code inside the template is obfuscated by adding a lot of junk code. The VBScript code is obfuscated similar to the macro code.
Then the attackers used mshta.exe to download an XML file, which was likely masquerading as an HTML application file.
Sends a network request to download the next stage payload using the IP address obtained from step #2 and also exfiltrate the information collected from step #1 using the UserAgent field
Their primary objectives are to fingerprint the host system, update the network configuration in the registry using Dead Drop Resolvers (DDRs), fetch and execute arbitrary VBScript payloads from the C2 servers.
GammaLoad... resolves live C2 addresses by parsing Telegram and Cloudflare-hosted Dead Drop Resolver pages.
GammaLoad operates as a cascading four-stage VBScript downloader... and fetches final payloads.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used by Gamaredon as part of operations focused on persistence, propagation, and document theft.
A four-stage VBScript downloader used to fingerprint compromised hosts, resolve C2 through dead-drop-resolver pages, persist configuration in the registry, and retrieve later-stage payloads.
Intermediate staging layer composed of VBScript loaders that fingerprint the host, update network configuration in the registry using dead drop resolvers, and fetch and execute arbitrary VBScript payloads from C2 servers.
A loader in the infection chain that is likely deployed by GammaPhish and used to deliver other Gamaredon malware families such as GammaSteel, and possibly GammaWorm or GammaWipe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.