Threat reportMalwareTL-2026-0653
Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
Gamaredon (Russia/FSB) "GammaWorm" (TL-2026-0653), also tracked as Gamma toolset campaign, is a high-severity malware campaign, first published 2026-06-02. It is attributed to Gamaredon (Russia) with high confidence, affects RARLAB WinRAR (Windows), references 1 CVE (CVE-2025-8088), maps to 26 MITRE ATT&CK techniques (T1005, T1008, T1025), and is covered by 9 detection rules and 42 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 26MITRE ATT&CK
- Actors
- 1Gamaredon
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 42Indicators of compromise
Key facts for TL-2026-0653
- Threat ID
- TL-2026-0653
- Also known as
- Gamma toolset campaign, GammaWorm campaign, FSB's matryoshka (Sekoia)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Gamaredon
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, military, defense, critical-infrastructure
- Target regions
- Ukraine, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 42
Malware and tooling in Gamaredon (Russia/FSB) "GammaWorm"
Malware and tooling: GammaPhish, GammaWorm, mshta.exe / wscript.exe / curl.exe (LOLBins)
How Gamaredon (Russia/FSB) "GammaWorm" works
Gamaredon, the FSB Center 18 espionage group, is running an ongoing campaign against Ukrainian government, military, and critical-infrastructure networks using a reorganized modular 'Gamma' toolset (GammaPhish, GammaLoad, GammaWorm, GammaSteel). Initial access uses weaponized xHTML lures that HTML-smuggle a malicious RAR exploiting WinRAR path-traversal CVE-2025-8088 to drop an HTA into the Windows Startup folder. GammaWorm is a 20,000-line VBScript that hides almost entirely inside NTFS Alternate Data Streams, persists via a RunOnce key and three scheduled tasks executing from hidden streams, worms across USB/network drives via malicious LNK shortcuts run through mshta.exe/wscript.exe, and uses Dead Drop Resolvers on Telegraph/Teletype/Telegram, Cloudflare Workers, and Cloudflare tunnels for resilient, rotating command-and-control.
Gamaredon (FSB Center 18 for Information Security, operating from occupied Crimea; attributed by the Security Service of Ukraine) has reorganized its long-running Ukraine espionage arsenal into a modular 'Gamma' ecosystem with dedicated components for phishing (GammaPhish), staging (GammaLoad), worm-like propagation (GammaWorm), and data theft (GammaSteel). Sekoia analyzed the campaign in January 2026; it remains active and is the successor to the group's earlier Pteranodon/Pterodo frameworks (2016-2021) and the Ptero* tool family (PteroLNK, PteroOdd, PteroPaste, PteroGraphin).
INITIAL ACCESS (GammaPhish): The chain begins with a weaponized xHTML file (e.g. 1_13_5_1691_09.12.2025.xhtml) that displays a fake 'DOCUMENT DOWNLOADED' message while beaconing a tracking pixel to a Supabase Edge Function. A JavaScript OnError handler performs HTML smuggling — reconstructing a Base64-embedded RAR archive (2_14_6_1033_09.12.2025.rar) only for Windows User-Agents. The RAR abuses WinRAR path-traversal CVE-2025-8088 (CWE-35), carrying a decoy PDF plus an HTA whose extraction path traverses (..\..\..\..\..\..\) into the per-user Startup folder (AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2_14_6_1033_09.12.2025.HTA), guaranteeing execution at next logon. The HTA launches mshta.exe against a Supabase-hosted URL crafted with an '@' userinfo trick (hxxps://www.bbc.com@<supabase host>/...capture.pdf) to masquerade as a benign domain.
GammaWorm (PROPAGATION & PERSISTENCE): The core implant is a single VBScript of more than 20,000 lines (~90% junk/obfuscation) delivered as '~.gif' and assembled in memory via ExecuteGlobal. It hides its body in NTFS Alternate Data Streams: a primary clone at %USERPROFILE%:GTR, a fallback at %USERPROFILE%\boot.ini, and a killswitch stream %USERPROFILE%:save (activates if it exceeds 100 bytes). Persistence is layered: a RunOnce value HKCU\...\RunOnce\ExplorerGuard relaunches wscript.exe against the ADS copy, and three scheduled tasks masquerading as Windows maintenance jobs — DiskDiagnosticDataCollector (7 min; reads ADS :URL for DDR C2 resolution), SilentCleanup (7 min; reads ADS :LNK for USB/network propagation), and SmartRetry (10 min; reads ADS :SERVER for a DDR clone) — execute code directly from the hidden streams. The worm also tampers with Explorer\Advanced settings (Hidden=0x2, ShowSuperHidden=0x0, HideFileExt=0x1) to conceal files and extensions.
Worming: A WMI query (select * from win32_logicaldisk where mediatype=null) enumerates fixed network/USB drives. GammaWorm writes a full '~.gif' copy to each drive root, sets Hidden+System attributes on legitimate folders, and replaces them with LNK shortcuts that carry folder icons and names. The dual-execution LNK runs an mshta.exe javascript: eval that both opens the real folder via explorer and silently launches 'wscript.exe ~.gif //b //e:vbScript'. Decoy LNKs use provocative Ukrainian-language lures (e.g. 'таємно.doc', 'карта обліку.doc', 'фото військовополоненого.jpeg', 'згвалтування.jpeg', 'порно-фото.jpeg'). Propagation recurses to a 4-folder depth.
COMMAND & CONTROL (Dead Drop Resolvers): GammaWorm resolves live C2 through Dead Drop Resolvers rather than hardcoded servers. Hardcoded seed pages live on Telegraph/Teletype and Telegram (graph.org/kyjfkyr-12-06, telegra.ph/f8bfl6sp-01-02, t.me/s/teotori, www.telegram.me/s/oberfarir); the worm pulls these (including via curl.exe), parses embedded URLs/IPs in a five-loop recursive chain, and caches each tier in HKCU\Console\ values (WindowsUpdates/WindowsResponby for the primary C2 domain, WindowsDetect/URLTeletype for Teletype, WindowsTelegra/URLTelegra for Telegraph, IpURL for a direct-IP fallback). Observed staging infrastructure includes Cloudflare Workers subdomains (bold.zsjtn41091.workers.dev), a Cloudflare quick tunnel (efficiency-planes-emotions-fascinating.trycloudflare.com), an operator domain (quitethepastry.ru), and a direct C2 IP (104.194.140.6). This hybrid design enables rapid rotation, hides staging behind Cloudflare, and falls back to direct IPs if cloud services are disrupted.
BACKDOOR LOOP & EXFIL: A continuous loop (28-second sleep) beacons to the resolved C2, encoding host fingerprints (ComputerName, hex drive serial, random strings) into randomized HTTP headers to mimic normal web traffic — a structured User-Agent with rotating separators (::, ##, !!, ??, ==), spoofed Referer values (.gov.ua/.mil.gov.ua/.nato.int/.gov.md), randomized Cookie names/values, varied Accept-Language q-values, and random Content-Length (2916-6966 bytes). On HTTP 200 with no <html> tag the response is Base64-decoded, stripped of CR/'&&' markers, and run via ExecuteGlobal for in-memory execution; on HTTP 404 the response delimiters update the registry C2 configuration. Because every stage can re-profile the host, update config, and fetch fresh payloads, the chain behaves as a stack of redundant backdoors — partial cleanup leaves surviving components able to restore access.
STRATEGIC SIGNIFICANCE: The same Gamaredon tooling has been used to hand access to Turla (FSB Center 16) for Kazuar deployment (ESET, Sept 2025), underscoring that a GammaWorm foothold can be a precursor to higher-tier intrusion. The campaign's combination of fileless VBScript, ADS concealment, USB-borne worming, and cloud-backed DDR C2 substantially raises stealth and durability over earlier Gamaredon frameworks.
MITRE ATT&CK techniques used in TL-2026-0653
Collection
T1005 Data from Local System; T1025 Data from Removable Media
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1211 Exploitation for Stealth; T1218 System Binary Proxy Execution; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution
Lateral Movement
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery
Initial Access
T1091 Replication Through Removable Media; T1566 Phishing
defense-impairment
Persistence
T1547 Boot or Logon Autostart Execution
Resource Development
Affected products and versions in Gamaredon (Russia/FSB) "GammaWorm"
- RARLAB — WinRAR (Windows)
Vulnerable versions: <= 7.12
Fixed in: 7.13 - RARLAB — UnRAR.dll / WinRAR command-line (Windows)
Vulnerable versions: <= 7.12
Fixed in: 7.13 - Microsoft — Windows (NTFS / Windows Script Host / mshta)
Vulnerable versions: 10; 11; Server 2016-2022
Remediation for Gamaredon (Russia/FSB) "GammaWorm"
Patches
- WinRAR 7.13 (fixes CVE-2025-8088) — https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283
Immediate actions
- Update WinRAR to 7.13 or later to remediate CVE-2025-8088 (no auto-update in WinRAR; manual install required).
- Block/monitor the listed DDR seed pages and C2 (graph.org/kyjfkyr-12-06, telegra.ph/f8bfl6sp-01-02, t.me/s/teotori, telegram.me/s/oberfarir, bold.zsjtn41091.workers.dev, quitethepastry.ru, *.trycloudflare.com, 104.194.140.6).
- Hunt for NTFS ADS on user-profile paths (%USERPROFILE%:GTR, %USERPROFILE%:save, %USERPROFILE%:URL, :LNK, :SERVER) and on boot.ini in the profile.
- Inspect HKCU RunOnce\ExplorerGuard and HKCU\Console\ values (WindowsUpdates, WindowsResponby, WindowsDetect, URLTeletype, WindowsTelegra, URLTelegra, IpURL) and remove.
- Disable/quarantine rogue scheduled tasks named DiskDiagnosticDataCollector, SilentCleanup, SmartRetry that invoke wscript.exe/mshta.exe against ADS.
Workarounds
- Until WinRAR is updated, avoid extracting untrusted archives; consider an alternative archiver.
- Set HKCU\...\Explorer\Advanced Hidden=1/ShowSuperHidden=1/HideFileExt=0 via GPO and monitor for reversion.
- Block the '@' userinfo URL pattern and HTML-smuggling content at the web proxy.
Longer-term hardening
- Deploy EDR with behavioral detection for mshta.exe/wscript.exe spawning from LNK and reading from ADS; alert on curl.exe to telegram/telegraph.
- Restrict or block mshta.exe and wscript.exe execution via WDAC/AppLocker where business needs allow.
- Enforce removable-media controls and disable AutoRun; flag LNK files that hide folders with Hidden+System attributes.
- Egress-filter and inspect traffic to Telegraph/Teletype/Telegram, *.workers.dev, and *.trycloudflare.com for DDR abuse.
- Sweep for downstream Turla/Kazuar activity on any host showing Gamaredon Ptero/Gamma artifacts.
CVEs associated with Gamaredon (Russia/FSB) "GammaWorm"
Weaknesses (CWE) in Gamaredon (Russia/FSB) "GammaWorm"
Timeline of Gamaredon (Russia/FSB) "GammaWorm"
- Gamaredon active since at least 2013; attributed by Ukraine's SSU to FSB Center 18 (Center for Information Security), operating from occupied Crimea.
- Group operated the Pteranodon/Pterodo framework (2016-2021) before transitioning to modular standalone Ptero* and Gamma families.
- WinRAR path-traversal CVE-2025-8088 disclosed and patched in WinRAR 7.13; discovered by ESET (Cherepanov, Kosinar, Strycek), already exploited in the wild by multiple groups.
- ESET documents Gamaredon handing access to Turla (FSB Center 16) to deploy Kazuar in Ukraine, confirming Gamaredon footholds as precursors to higher-tier intrusion.
- Weaponized GammaPhish xHTML/RAR lures dated 09.12.2025 observed (e.g. 1_13_5_1691_09.12.2025.xhtml, 2_14_6_1033_09.12.2025.rar).
- Sekoia analyzes the Gamma-toolset campaign (GammaPhish/GammaWorm), detailing NTFS-ADS concealment and cloud Dead Drop Resolver C2; campaign assessed ongoing.
- Public reporting (Cyber Security News, citing Sekoia) details GammaWorm hiding in Windows features and abusing cloud platforms for C2.
Sources cited for Gamaredon (Russia/FSB) "GammaWorm"
- Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2
- FSB's matryoshka #1/3: Inside Gamaredon Cyber Operations (GammaPhish & GammaWorm)
- Gamaredon X Turla collab — FSB groups collaborate to deploy Kazuar in Ukraine
- NVD — CVE-2025-8088 (WinRAR path traversal, exploited in the wild)
- CISA Known Exploited Vulnerabilities — CVE-2025-8088
- WinRAR 7.13 release advisory (fixes CVE-2025-8088)
- ESET — Update WinRAR tools now: RomCom and others exploiting CVE-2025-8088 zero-day
- ESET — Gamaredon in 2024 (white paper)
Detection coverage for TL-2026-0653
As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0653 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.