Gamaredon Deploys GammaDrop and GammaLoad In Phishing Campaigns
ID: 76ae8229-73ab-5fb3-aa02-5a1b86e65f1f
STIX ID: report--76ae8229-73ab-5fb3-aa02-5a1b86e65f1f
Feed Name: Cyber Press
Gamaredon (aka Aqua Blizzard/Shuckworm) has run multiple targeted spearphishing waves since September 2025 against Ukrainian government institutions by weaponizing CVE-2025-8088 (a critical WinRAR directory traversal). Malicious RAR archives drop a VBScript first-stage (GammaDrop) that fetches an obfuscated second-stage (GammaLoad) from Cloudflare Workers and fallback domains, establishing persistence and selective destructive capability; the report includes three SHA-256 IOCs and describes the attack chain, delivery methods, and C2 behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
