logo

Gamaredon Exploits WinRAR Path Traversal to Unleash GammaDrop Malware

ID: 0a2f4365-6a93-5801-b054-48b807a13165

STIX ID: report--0a2f4365-6a93-5801-b054-48b807a13165

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

HarfangLab documents an active Gamaredon spearphishing campaign (since Sept 2025 and ongoing) abusing WinRAR path traversal (CVE-2025-8088) to drop obfuscated VBS downloaders (GammaDrop → GammaLoad) that establish persistence via the Startup folder and beacon to Cloudflare-proxied C2 and fallback domains; the campaign targets Ukrainian government, military, and SSU directorates and uses fast-flux, dynamic DNS, compromised email relays, and evolving archive formats to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.