Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access — Threadlinqs Intelligence
As of 2026-06-02, Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access is a high-severity malware threat attributed to Gamaredon (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-0653 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Gamaredon · Russia · ESPIONAGE
Gamaredon, the FSB Center 18 espionage group, is running an ongoing campaign against Ukrainian government, military, and critical-infrastructure networks using a reorganized modular 'Gamma' toolset
Gamaredon (FSB Center 18 for Information Security, operating from occupied Crimea; attributed by the Security Service of Ukraine) has reorganized its long-running Ukraine espionage arsenal into a modular 'Gamma' ecosystem with dedicated components for phishing (GammaPhish), staging (GammaLoad), worm-like propagation (GammaWorm), and data theft (GammaSteel). Sekoia analyzed the campaign in January 2026; it remains active and is the successor to the group's earlier Pteranodon/Pterodo frameworks (2016-2021) and the Ptero* tool family (PteroLNK, PteroOdd, PteroPaste, PteroGraphin).
INITIAL ACCESS (GammaPhish): The chain begins with a weaponized xHTML file (e.g. 1_13_5_1691_09.12.2025.xhtml) that displays a fake 'DOCUMENT DOWNLOADED' message while beaconing a tracking pixel to a Supabase Edge Function. A JavaScript OnError handler performs HTML smuggling — reconstructing a Base64-embedded RAR archive (2_14_6_1033_09.12.2025.rar) only for Windows User-Agents. The RAR abuses WinRAR path-traversal CVE-2025-8088 (CWE-35), carrying a decoy PDF plus an HTA whose extraction path traverses (..\..\..\..\..\..\) into the per-user Startup folder (AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2_14_6_1033_09.12.2025.HTA), guaranteeing execution at next logon. The HTA launches mshta.exe against a Supabase-hosted URL crafted with an '@' userinfo trick (hxxps://www.bbc.com@<supabase host>/...capture.pdf) to masquerade as a benign domain.
GammaWorm (PROPAGATION & PERSISTENCE): The core implant is a single VBScript of more than 20,000 lines (~90% junk/obfuscation) delivered as '~.gif' and assembled in memory via ExecuteGlobal. It hides its body in NTFS Alternate Data Streams: a primary clone at %USERPROFILE%:GTR, a fallback at %USERPROFILE%\boot.ini, and a killswitch stream %USERPROFILE%:save (activates if it exceeds 100 bytes). Persistence is layered: a RunOnce value HKCU\...\RunOnce\ExplorerGuard relaunches wscript.exe against the ADS copy, and three scheduled tasks masquerading as Windows maintenance jobs — DiskDiagnosticDataCollector (7 min; reads ADS :URL for DDR C2 resolution), SilentCleanup (7 min; reads ADS :LNK for USB/network propagation), and SmartRetry (10 min; reads ADS :SERVER for a DDR clone) — execute code directly from the hidden streams. The worm also tampers with Explorer\Advanced settings (Hidden=0x2, ShowSuperHidden=0x0, HideFileExt=0x1) to conceal files and extensions.
Worming: A WMI query (select * from win32_logicaldisk where mediatype=null) enumerates fixed network/USB drives. GammaWorm writes a full '~.gif' copy to each drive root, sets Hidden+System attributes on legitimate folders, and replaces them with LNK shortcuts that carry folder icons and names. The dual-execution LNK runs an mshta.exe javascript: eval that both opens the real folder via explorer and silently launches 'wscript.exe ~.gif //b //e:vbScript'. Decoy LNKs use provocative Ukrainian-language lures (e.g. 'таємно.doc', 'карта обліку.doc', 'фото військовополоненого.jpeg', 'згвалтування.jpeg', 'порно-фото.jpeg'). Propagation recurses to a 4-folder depth.
COMMAND & CONTROL (Dead Drop Resolvers): GammaWorm resolves live C2 through Dead Drop Resolvers rather than hardcoded servers. Hardcoded seed pages live on Telegraph/Teletype and Telegram (graph.org/kyjfkyr-12-06, telegra.ph/f8bfl6sp-01-02, t.me/s/teotori, www.telegram.me/s/oberfarir); the worm pulls these (including via curl.exe), parses embedded URLs/IPs in a five-loop recursive chain, and caches each tier in HKCU\Console\ values (WindowsUpdates/WindowsResponby for the primary C2 domain, WindowsDetect/URLTeletype for Teletype, WindowsTelegra/URLTelegra for Telegraph, IpURL for a direct-IP fallback). Observed staging infrastructure includes Cloudflare Workers subdomains (bold.zsjtn41091.workers.dev), a Cloudflare quick tunnel (efficiency-planes-emotions-fascinating.trycloudflare.com), an operator domain (quitethepastry.ru), and a direct C2 IP (104.194.140.6). This hybrid design enables rap
Target sectors: government, military, defense, critical-infrastructure
Target regions: Ukraine, Eastern Europe
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2025-8088, T1583, T1608, T1566, T1091, T1204, T1059, T1053, T1047, T1547, T1564