GammaPhish is the initial-access component in Gamaredon’s modular “Gamma” malware ecosystem, a Russia-linked cyberespionage toolset used primarily against Ukrainian government, military, and critical infrastructure organizations. It is associated with the FSB-linked threat actor Gamaredon, also tracked as Armageddon, Primitive Bear, ACTINIUM, and related aliases. GammaPhish is designed to establish footholds on Windows systems and hand off execution to later-stage Gamma components, especially GammaLoad, which can then retrieve and execute additional payloads such as GammaWorm, GammaSteel, and potentially destructive tooling.
Observed GammaPhish activity uses weaponized XHTML lure files, likely delivered through spearphishing, to initiate infection. These lures employ HTML smuggling to deliver a malicious RAR archive that exploits CVE-2025-8088, a WinRAR path traversal vulnerability. The exploit places a hidden HTA payload into the user’s Startup directory so that it executes via mshta.exe at the next logon, providing persistence and code execution without requiring a conventional installer. GammaPhish then retrieves a VBScript staging payload from remote infrastructure. In the broader intrusion chain, this stage supports host fingerprinting, registry-based configuration updates through dead-drop resolver logic, and retrieval of arbitrary VBScript from command-and-control infrastructure.
The malware family reflects Gamaredon’s shift toward a fragmented, resilient, script-heavy architecture that emphasizes stealth, rapid iteration, and recovery of access even after partial remediation. Campaigns involving GammaPhish have abused legitimate online services and cloud-hosted intermediaries to conceal command-and-control discovery and blend malicious traffic with normal activity. GammaPhish is therefore best understood as a delivery and execution stage within a larger espionage framework rather than a standalone stealer or worm.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits CVE-2025-8088, a critical path traversal flaw in WinRAR patched in version 7.13. | Sekoia has now aligned the naming under a single taxonomy using the “Gamma” prefix: GammaPhish for initial access... “GammaPhish (Initial access): Through YARA-based hunting, we identified a cluster of weaponized xHTML files distributing a malicious RAR archive. This archive exploits the CVE-2025-8088 vulnerability to extract a hidden HTA file directly into the user’s Windows Startup directory.”
Applying this convention, we have established the following naming patterns: GammaPhish: All stages from the initial phishing email up to the deployment of GammaLoad (some stages are formerly known as GammaDrop, PteroDoc).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon used GammaPhish, GammaWorm, GammaLoad, and GammaSteel to establish persistence, achieve physical propagation, and steal documents, actively exploiting legitimate Services, cloud storage, and tunneling infrastructure.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Its malware ecosystem, including GammaPhish and GammaWorm, enables USB-based propagation across air-gapped systems, document theft, and continuous deployment of additional payloads
the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR
The extracted HTA file contains a VBScript blob comprising approximately 90% of junk and obfuscated code.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/tooling used by Gamaredon as part of a toolkit for persistence, propagation, and document theft.
Initial access component used by Gamaredon to deliver a malicious RAR archive via weaponized XHTML/HTML smuggling, exploiting a WinRAR path traversal flaw to place an HTA file in Startup for execution.
An HTML Application payload used in the infection chain to fetch VBScript payloads from C2 and likely deploy GammaLoad first.
An HTML Application payload used in the Gamaredon infection chain to initiate execution and retrieve the intermediate VBScript downloader GammaLoad.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.