logo

FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad

ID: 08a983dc-8d83-5ad3-86af-64e3e9628ca2

STIX ID: report--08a983dc-8d83-5ad3-86af-64e3e9628ca2

Feed Name: Sekoia.io Blog (archive)

Threat Score
88/100

Date Published: 2026-06-03

Date Updated: 2026-07-19

Author: Amaury G. and Sekoia TDR

...
...

**Sekoia.io TDR analysis of Gamaredon’s GammaLoad:** This report analyzes GammaLoad, a three-stage chain of VBScript and obfuscated PowerShell loaders used by the FSB-linked Gamaredon intrusion set to stage and deploy the GammaSteel stealer; it documents registry-based C2 caching under HKCU\Console, use of Dead Drop Resolvers (Telegraph/Telegram/Check-Host) to retrieve C2, the in-memory execution and ADS dropper behaviors, scheduled-task persistence for periodic execution, and provides sample file hashes and network IOCs observed during active interaction with the actor’s infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.