logo

FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm

ID: 43eac096-a0e4-5607-b96e-f6fc96974845

STIX ID: report--43eac096-a0e4-5607-b96e-f6fc96974845

Feed Name: Sekoia.io Blog

Threat Score
92/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Amaury G. and Sekoia TDR

...
...

**Sekoia.io documents an active, high‑sophistication Gamaredon (Russian FSB‑linked) espionage campaign observed in January 2026 that uses HTML smuggling and a WinRAR path‑traversal exploit (CVE‑2025‑8088) to deploy a modular toolset (GammaPhish, GammaLoad, GammaWorm, GammaSteel) which leverages NTFS Alternate Data Streams, scheduled tasks, USB propagation, and Dead Drop Resolvers (Telegram/Cloudflare) to maintain persistent backdoors and exfiltrate sensitive documents.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.