logo

Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign

ID: 9ff81201-4ab1-55eb-b86f-98ec83fd909e

STIX ID: report--9ff81201-4ab1-55eb-b86f-98ec83fd909e

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

...
...

Gamaredon, a Russian state‑linked APT, is actively exploiting WinRAR vulnerability CVE-2025-8088 to deliver a modular malware suite (GammaPhish, GammaLoad, GammaWorm, GammaSteel) against Ukrainian government, military, and critical infrastructure; the infection chain uses spearphishing RAR attachments, an HTML Application payload and VBScript loaders to fetch a self‑propagating worm that hides components in NTFS Alternate Data Streams and leverages cloud services (Telegram, Cloudflare, Supabase) for C2, with recommendations including WinRAR updates, ADS and scheduled task detections, network blocking of known resolvers, and full system rebuilds due to persistent and resilient infection mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.