Gamaredon Deploys GammaDrop, GammaLoad in Phishing Campaigns
ID: 73d8a2a0-ad6f-51d8-9cd5-cc3ffa449d28
STIX ID: report--73d8a2a0-ad6f-51d8-9cd5-cc3ffa449d28
Feed Name: GBHackers
Gamaredon (also tracked as UAC-0010/Shuckworm) is running sustained multi-stage phishing campaigns against Ukrainian government organizations by exploiting WinRAR CVE-2025-8088 to drop obfuscated VBScript loaders (GammaDrop and GammaLoad) via RAR/ARJ archives and NTFS ADS; GammaLoad persists via RunOnce, collects system identifiers, beacons periodically to Cloudflare Workers-hosted C2 (with fallbacks on Russian domains), and operators rotate infrastructure and abuse weak email authentication—recommended mitigations include patching WinRAR, enforcing SPF/DKIM/DMARC, and blocking known malicious IP ranges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
