3: Inside Gamaredon Cyber Operations
ID: 87f6c330-b4db-59d3-8364-630be055bc9b
STIX ID: report--87f6c330-b4db-59d3-8364-630be055bc9b
Feed Name: Sekoia.com
Sekoia.io TDR documents a January 2026 Gamaredon intrusion chain targeting Ukrainian government and critical infrastructure, detailing initial phishing (GammaPhish) exploiting CVE-2025-8088 to drop an HTA that fetches loaders (GammaLoad), a VBScript-based propagating worm (GammaWorm) using NTFS ADS and LNK-based USB/network propagation, and a modular PowerShell stealer (GammaSteel) that stages modules in the registry and exfiltrates to S3-compatible storage; the report includes IOCs, Dead Drop Resolver and C2 infrastructure, and recommended hunting/detection opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
