GammaSteel is a modular data-theft malware family used by the Russia-linked Gamaredon espionage group as part of its broader "Gamma" malware ecosystem. Within that ecosystem, GammaSteel serves the exfiltration role alongside components used for phishing, staging, and worm-like propagation. It has been associated with long-running Gamaredon operations targeting Ukraine, particularly government, military, and critical infrastructure organizations.
GammaSteel has been described as a modular information stealer implemented in PowerShell. Observed variants collect files matching selected extensions and exfiltrate the stolen data to S3-compatible cloud storage, with fallback delivery to operator-controlled servers. Reporting also indicates that at least one variant stages numerous DPAPI-encrypted modules in the Windows registry, reflecting an emphasis on modularity and concealment.
GammaSteel is delivered through the GammaLoad staging component in multi-stage intrusion chains. In documented campaigns, initial access was achieved through spearphishing lures using weaponized XHTML attachments and malicious RAR archives exploiting CVE-2025-8088 in WinRAR. The broader Gamaredon architecture is designed so multiple stages can independently retrieve and execute fresh payloads, contributing to resilience and complicating remediation.
Use of GammaSteel fits Gamaredon's established cyberespionage mission: theft of victim documents from Ukrainian targets while blending malicious activity with legitimate services and cloud infrastructure. Its role, modular design, and cloud-based exfiltration mechanisms are consistent with an operational focus on persistent access, stealth, and efficient collection of sensitive files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to Sekoia, the attack consists of exploiting the bug CVE-2025-8088, a path traversal bug in WinRAR, to run an HTML App payload called GammaPhish, which is later used to get a VBScript payload from the C2 server.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon used GammaPhish, GammaWorm, GammaLoad, and GammaSteel to establish persistence, achieve physical propagation, and steal documents, actively exploiting legitimate Services, cloud storage, and tunneling infrastructure.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Kimsuky used malicious LNK files, the Dropbox API, GitHub Releases, and Google Drive for Information Theft and command execution.
GammaSteel manages three concurrent data acquisition mechanisms: recurring scans of local and network drives, hardware event monitoring for newly inserted USBs...
GammaSteel manages three concurrent data acquisition mechanisms: recurring scans of local and network drives...
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Document-stealing malware used by Gamaredon in campaigns emphasizing persistence and propagation.
Data theft component in Gamaredon’s modular malware taxonomy.
A modular information stealer that collects files with selected extensions and exfiltrates them to an AWS S3 bucket or attacker-controlled backup server.
A modular information stealer that collects files matching selected extensions and exfiltrates them to AWS S3 or an attacker-controlled server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.