Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
ID: 63f8b3a2-43a9-57f7-be9e-04f273352c92
STIX ID: report--63f8b3a2-43a9-57f7-be9e-04f273352c92
Feed Name: Security Affairs
Gamaredon leverages a WinRAR path-traversal (CVE-2025-8088) via weaponized XHTML attachments to HTML-smuggle a RAR that extracts an HTA into Startup, initiating a multi-stage VBScript-based, nearly fileless infection chain (GammaPhish → GammaLoad → GammaWorm). The campaign uses NTFS Alternate Data Streams for stealth, scheduled tasks and RunOnce registry tricks for persistence, USB and share-based propagation with deceptive LNK files, and resolves C2s through a layered dead-drop chain including Telegram and Cloudflare; IOCs and remediation advice (full host wipe recommended) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
