Gamaredon Exploits WinRAR Path Traversal to Unleash GammaDrop Malware
ID: 0a2f4365-6a93-5801-b054-48b807a13165
STIX ID: report--0a2f4365-6a93-5801-b054-48b807a13165
Feed Name: securityonline.info
HarfangLab documents an active Gamaredon spearphishing campaign (since Sept 2025 and ongoing) abusing WinRAR path traversal (CVE-2025-8088) to drop obfuscated VBS downloaders (GammaDrop → GammaLoad) that establish persistence via the Startup folder and beacon to Cloudflare-proxied C2 and fallback domains; the campaign targets Ukrainian government, military, and SSU directorates and uses fast-flux, dynamic DNS, compromised email relays, and evolving archive formats to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
