logo

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

ID: 63f8b3a2-43a9-57f7-be9e-04f273352c92

STIX ID: report--63f8b3a2-43a9-57f7-be9e-04f273352c92

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Pierluigi Paganini

...
...

Gamaredon leverages a WinRAR path-traversal (CVE-2025-8088) via weaponized XHTML attachments to HTML-smuggle a RAR that extracts an HTA into Startup, initiating a multi-stage VBScript-based, nearly fileless infection chain (GammaPhish → GammaLoad → GammaWorm). The campaign uses NTFS Alternate Data Streams for stealth, scheduled tasks and RunOnce registry tricks for persistence, USB and share-based propagation with deceptive LNK files, and resolves C2s through a layered dead-drop chain including Telegram and Cloudflare; IOCs and remediation advice (full host wipe recommended) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.