logo

Gamaredon Deploys GammaDrop and GammaLoad In Phishing Campaigns

ID: 76ae8229-73ab-5fb3-aa02-5a1b86e65f1f

STIX ID: report--76ae8229-73ab-5fb3-aa02-5a1b86e65f1f

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-18

Date Updated: 2026-05-22

Author: Varshini

...
...

Gamaredon (aka Aqua Blizzard/Shuckworm) has run multiple targeted spearphishing waves since September 2025 against Ukrainian government institutions by weaponizing CVE-2025-8088 (a critical WinRAR directory traversal). Malicious RAR archives drop a VBScript first-stage (GammaDrop) that fetches an obfuscated second-stage (GammaLoad) from Cloudflare Workers and fallback domains, establishing persistence and selective destructive capability; the report includes three SHA-256 IOCs and describes the attack chain, delivery methods, and C2 behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.