Researchers attributed a January 2026 cyberespionage campaign against Ukrainian government, military, and critical infrastructure organizations to the Russia-linked Gamaredon group, which used booby-trapped spearphishing attachments and malicious RAR archives exploiting WinRAR path traversal flaw CVE-2025-8088 for initial access. The infection chain dropped an HTA payload dubbed GammaPhish, which launched via mshta.exe and fetched follow-on VBScript components including GammaLoad, GammaWorm, and GammaSteel. Sekoia said the operation marks a shift from Gamaredon’s older Pteranodon tooling to a fragmented, modular ecosystem in which multiple stages can independently act as backdoors and retrieve arbitrary remote code.
The malware emphasized stealth, persistence, and resilient command-and-control. GammaWorm established persistence through scheduled tasks and RunOnce registry keys, hid modules in NTFS Alternate Data Streams, and spread through USB devices and network shares using malicious LNK shortcuts, including into air-gapped environments. Command-and-control discovery relied on dead-drop resolvers hosted on Telegram, Telegra.ph, graph.org, Teletype, Cloudflare Workers, and operator infrastructure, while GammaSteel staged dozens of DPAPI-encrypted modules in the registry and exfiltrated selected files to AWS S3 or other S3-compatible storage with fallback to attacker-controlled servers. Because fresh payloads can be fetched at multiple stages, researchers warned that confirmed compromises may require full system wiping.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that at least two Russia-aligned clusters, Shadow-Earth-066 and Earth Dahu (Gamaredon), exploited WinRAR path traversal flaw CVE-2025-8088 in email attacks against Ukrainian military and government organizations. The report said Shadow-Earth-066 used the flaw to deploy an updated GiftedCrook stealer, while Gamaredon used HTA and VBScript stages to deliver espionage modules.
Sekoia analyzed a January 2026 Gamaredon intrusion chain targeting Ukrainian government, military, and critical infrastructure entities. The campaign used weaponized xHTML files and a malicious RAR archive exploiting WinRAR path traversal vulnerability CVE-2025-8088 for initial access.
Gurucul published a high-severity threat notice summarizing the Gamaredon activity and providing indicators of compromise, including URLs, an IP address, MD5 hashes, and detection queries. The notice cited Sekoia's reporting as its source.
On June 1, 2026, Sekoia published a report reconstructing the modular espionage chain and introducing the GammaPhish, GammaLoad, GammaWorm, GammaSteel, and GammaWipe taxonomy. The report said Gamaredon had shifted away from its historical Pteranodon framework toward a fragmented ecosystem in which multiple stages can independently act as backdoors and fetch remote code.
WinRAR fixed the path traversal vulnerability CVE-2025-8088 in version 7.13 in July 2025. The flaw allowed attackers to write files outside the extraction directory via NTFS Alternate Data Streams, including into the Windows Startup folder for execution at next login.
Cisco Talos published reporting on Gamaredon activity, providing historical context on the threat actor referenced by later coverage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcefreebuf.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourceblog.sekoia.io
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.