GammaSteel is a modular PowerShell information stealer used by the Russia-linked Gamaredon cyberespionage group, also tracked as Armageddon, UAC-0010, and Primitive Bear. It is part of Gamaredon’s Gamma malware ecosystem and is deployed through the GammaLoad staging component. GammaSteel stores 71 DPAPI-encrypted PowerShell modules in the Windows registry, monitors local disks, network shares, and removable USB media for files matching operator-selected extensions, and exfiltrates collected files to S3-compatible cloud storage. It can fall back to attacker-controlled command-and-control infrastructure when cloud exfiltration is unavailable. Gamaredon has principally used this tooling against Ukrainian government, military, and critical-infrastructure organizations in long-running espionage operations. GammaSteel has been associated with intrusion chains initiated through spearphishing lures and weaponized archives exploiting CVE-2025-8088 in WinRAR.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Gamaredon and UAC-0226 are actively exploiting CVE-2025-8088, a CVSS 8.8 WinRAR path traversal flaw, to place malicious payloads outside the intended RAR extraction directory, including in the Windows Startup folder.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GammaSteel deploys 71 DPAPI-encrypted PowerShell modules into the Windows registry. It monitors local drives, network shares, and USB insertions in real time, exfiltrating targeted files to an S3-compatible cloud storage bucket with a fallback to attacker-controlled C2 servers.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
GIFTEDCROOK... [targets] documents matching specific extensions from the victim's machine. GammaSteel... monitors local drives, network shares, and USB insertions in real time [for] targeted files.
GammaSteel manages three concurrent data acquisition mechanisms: recurring scans of local and network drives, hardware event monitoring for newly inserted USBs...
GammaSteel manages three concurrent data acquisition mechanisms: recurring scans of local and network drives...
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Document-stealing malware used by Gamaredon in campaigns emphasizing persistence and propagation.
A modular collection and exfiltration payload that stages encrypted PowerShell modules in the registry, monitors local and removable/network storage, and sends targeted files to cloud storage or attacker C2 infrastructure.
Data theft component in Gamaredon’s modular malware taxonomy.
A modular information stealer that collects files with selected extensions and exfiltrates them to an AWS S3 bucket or attacker-controlled backup server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.