GammaPhish is a Windows initial-access and staging component in Gamaredon’s modular Gamma malware ecosystem. The Russia-linked, FSB-attributed Gamaredon group has used it in cyberespionage operations against Ukrainian government, military, and critical-infrastructure organizations. GammaPhish is delivered through spearphishing lures using weaponized XHTML attachments that employ HTML smuggling to provide a malicious RAR archive. The archive exploits CVE-2025-8088, a WinRAR path-traversal vulnerability, to place a hidden HTML Application in the user Startup folder. On a subsequent user login, the HTML Application executes through mshta.exe and retrieves the GammaLoad VBScript downloader from remote infrastructure. GammaPhish therefore serves as the delivery bridge between phishing-based intrusion and the subsequent GammaLoad staging chain, which can deploy additional Gamaredon components including GammaWorm and GammaSteel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Gamaredon and UAC-0226 are actively exploiting CVE-2025-8088, a CVSS 8.8 WinRAR path traversal flaw, to place malicious payloads outside the intended RAR extraction directory, including in the Windows Startup folder.
Applying this convention, we have established the following naming patterns: GammaPhish: All stages from the initial phishing email up to the deployment of GammaLoad (some stages are formerly known as GammaDrop, PteroDoc).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On next login, Windows auto-executes the HTA file. It is called mshta.exe, with a remote payload URL disguised by a fake BBC.com prefix, which retrieves and executes GammaLoad.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Its malware ecosystem, including GammaPhish and GammaWorm, enables USB-based propagation across air-gapped systems, document theft, and continuous deployment of additional payloads
the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR
The extracted HTA file contains a VBScript blob comprising approximately 90% of junk and obfuscated code.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/tooling used by Gamaredon as part of a toolkit for persistence, propagation, and document theft.
Gamaredon HTA-based execution stage that retrieves and launches the GammaLoad downloader after persistence through the Windows Startup folder.
Initial access component used by Gamaredon to deliver a malicious RAR archive via weaponized XHTML/HTML smuggling, exploiting a WinRAR path traversal flaw to place an HTA file in Startup for execution.
An HTML Application payload used in the infection chain to fetch VBScript payloads from C2 and likely deploy GammaLoad first.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.