GammaWorm is a heavily obfuscated VBScript worm in the Gamaredon (Armageddon) malware ecosystem. It targets Windows systems and supports Russia-linked cyberespionage operations against Ukrainian government, military, and critical-infrastructure organizations. GammaWorm conceals its modules in NTFS Alternate Data Streams, persists through scheduled tasks and a RunOnce registry entry, and modifies Explorer settings to reduce visibility of malicious artifacts. It propagates through removable USB media and network shares by hiding legitimate directories and substituting malicious Windows shortcut files that open the expected directory while also executing the worm. GammaWorm uses dead-drop resolver infrastructure, including public messaging and web services, to obtain command-and-control configuration. It collects and exfiltrates host fingerprinting data in HTTP headers and can retrieve and execute additional VBScript payloads, providing a resilient backdoor-like mechanism for sustained access and further operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Gamaredon and UAC-0226 are actively exploiting CVE-2025-8088, a CVSS 8.8 WinRAR path traversal flaw, to place malicious payloads outside the intended RAR extraction directory, including in the Windows Startup folder.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GammaWorm copies itself into NTFS Alternate Data Streams, creates three scheduled tasks, and writes a RunOnce registry key. It then propagates to USB drives and network shares by hiding legitimate directories and replacing them with malicious LNK shortcuts.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
GammaWorm copies itself into NTFS Alternate Data Streams, creates three scheduled tasks, and writes a RunOnce registry key.
resulting in the execution of arbitrary code retrieved from a command-and-control (C2) server
GammaWorm copies itself into NTFS Alternate Data Streams, creates three scheduled tasks, and writes a RunOnce registry key.
Next, to mask its future propagation activities, GammaWorm alters several registry keys within HKEY_USERS\[SID]\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\.
The hidden HTA payload is silently placed into the Windows Startup folder... GammaWorm... writes a RunOnce registry key. UAC-0226 places a Windows Shortcut (LNK) file directly into the Startup folder.
It hides real folders by setting their attributes to Hidden and System, then drops malicious LNK shortcut files in their place using the same folder name and icon. Clicking the LNK opens the real folder in Explorer so the user sees nothing wrong, while silently executing ~.gif, the worm file that sits at the root of every infected drive.
GammaWorm copies itself into NTFS Alternate Data Streams, creates three scheduled tasks, and writes a RunOnce registry key.
The hidden HTA payload is silently placed into the Windows Startup folder... GammaWorm... writes a RunOnce registry key. UAC-0226 places a Windows Shortcut (LNK) file directly into the Startup folder.
It hides real folders by setting their attributes to Hidden and System, then drops malicious LNK shortcut files in their place using the same folder name and icon. Clicking the LNK opens the real folder in Explorer so the user sees nothing wrong, while silently executing ~.gif, the worm file that sits at the root of every infected drive.
The extracted HTA file contains a VBScript blob comprising approximately 90% of junk and obfuscated code.
To find its C2 address, GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address... The C2 resolution chain itself is layered: it hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph, and Telegram before arriving at an operator-controlled server.
By using legitimate platforms like Telegram, the idea is to blend in with regular traffic, avoid detection, and sustain long-term espionage operations
To find its C2 address, GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address, and posts the victim’s machine fingerprint back via randomized HTTP headers, specifically inside the User-Agent string. No request body, just headers.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Worm component in Gamaredon's toolkit used for physical propagation, persistence, and document theft.
A persistent propagating component that hides in NTFS Alternate Data Streams, establishes scheduled-task and registry persistence, and spreads through USB drives and network shares using malicious LNK shortcuts.
Propagation-focused VBScript malware that spreads via USB drives and network shares, stores modules in NTFS Alternate Data Streams, maintains persistence with scheduled tasks and RunOnce abuse, resolves C2 through Telegram-based dead drops, and executes arbitrary VBScript from C2 responses.
A VBScript worm that establishes persistence via scheduled tasks, spreads through network shares and USB drives by replacing directories with malicious LNK files, uses Telegram for C2 resolution, and hides modules using NTFS Alternate Data Streams.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.