Threat reportMalwareTL-2026-0653

Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access

highACTIVE

Gamaredon (Russia/FSB) "GammaWorm" (TL-2026-0653), also tracked as Gamma toolset campaign, is a high-severity malware campaign, first published 2026-06-02. It is attributed to Gamaredon (Russia) with high confidence, affects RARLAB WinRAR (Windows), references 1 CVE (CVE-2025-8088), maps to 26 MITRE ATT&CK techniques (T1005, T1008, T1025), and is covered by 9 detection rules and 42 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
26MITRE ATT&CK
Actors
1Gamaredon
Detection rules
9SPL · KQL · Sigma
IOCs
42Indicators of compromise

Key facts for TL-2026-0653

Threat ID
TL-2026-0653
Also known as
Gamma toolset campaign, GammaWorm campaign, FSB's matryoshka (Sekoia)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Gamaredon
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, military, defense, critical-infrastructure
Target regions
Ukraine, Eastern Europe
Detection rules
9
Indicators of compromise
42

Malware and tooling in Gamaredon (Russia/FSB) "GammaWorm"

Malware and tooling: GammaPhish, GammaWorm, mshta.exe / wscript.exe / curl.exe (LOLBins)

How Gamaredon (Russia/FSB) "GammaWorm" works

Gamaredon, the FSB Center 18 espionage group, is running an ongoing campaign against Ukrainian government, military, and critical-infrastructure networks using a reorganized modular 'Gamma' toolset (GammaPhish, GammaLoad, GammaWorm, GammaSteel). Initial access uses weaponized xHTML lures that HTML-smuggle a malicious RAR exploiting WinRAR path-traversal CVE-2025-8088 to drop an HTA into the Windows Startup folder. GammaWorm is a 20,000-line VBScript that hides almost entirely inside NTFS Alternate Data Streams, persists via a RunOnce key and three scheduled tasks executing from hidden streams, worms across USB/network drives via malicious LNK shortcuts run through mshta.exe/wscript.exe, and uses Dead Drop Resolvers on Telegraph/Teletype/Telegram, Cloudflare Workers, and Cloudflare tunnels for resilient, rotating command-and-control.

Gamaredon (FSB Center 18 for Information Security, operating from occupied Crimea; attributed by the Security Service of Ukraine) has reorganized its long-running Ukraine espionage arsenal into a modular 'Gamma' ecosystem with dedicated components for phishing (GammaPhish), staging (GammaLoad), worm-like propagation (GammaWorm), and data theft (GammaSteel). Sekoia analyzed the campaign in January 2026; it remains active and is the successor to the group's earlier Pteranodon/Pterodo frameworks (2016-2021) and the Ptero* tool family (PteroLNK, PteroOdd, PteroPaste, PteroGraphin).

INITIAL ACCESS (GammaPhish): The chain begins with a weaponized xHTML file (e.g. 1_13_5_1691_09.12.2025.xhtml) that displays a fake 'DOCUMENT DOWNLOADED' message while beaconing a tracking pixel to a Supabase Edge Function. A JavaScript OnError handler performs HTML smuggling — reconstructing a Base64-embedded RAR archive (2_14_6_1033_09.12.2025.rar) only for Windows User-Agents. The RAR abuses WinRAR path-traversal CVE-2025-8088 (CWE-35), carrying a decoy PDF plus an HTA whose extraction path traverses (..\..\..\..\..\..\) into the per-user Startup folder (AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2_14_6_1033_09.12.2025.HTA), guaranteeing execution at next logon. The HTA launches mshta.exe against a Supabase-hosted URL crafted with an '@' userinfo trick (hxxps://www.bbc.com@<supabase host>/...capture.pdf) to masquerade as a benign domain.

GammaWorm (PROPAGATION & PERSISTENCE): The core implant is a single VBScript of more than 20,000 lines (~90% junk/obfuscation) delivered as '~.gif' and assembled in memory via ExecuteGlobal. It hides its body in NTFS Alternate Data Streams: a primary clone at %USERPROFILE%:GTR, a fallback at %USERPROFILE%\boot.ini, and a killswitch stream %USERPROFILE%:save (activates if it exceeds 100 bytes). Persistence is layered: a RunOnce value HKCU\...\RunOnce\ExplorerGuard relaunches wscript.exe against the ADS copy, and three scheduled tasks masquerading as Windows maintenance jobs — DiskDiagnosticDataCollector (7 min; reads ADS :URL for DDR C2 resolution), SilentCleanup (7 min; reads ADS :LNK for USB/network propagation), and SmartRetry (10 min; reads ADS :SERVER for a DDR clone) — execute code directly from the hidden streams. The worm also tampers with Explorer\Advanced settings (Hidden=0x2, ShowSuperHidden=0x0, HideFileExt=0x1) to conceal files and extensions.

Worming: A WMI query (select * from win32_logicaldisk where mediatype=null) enumerates fixed network/USB drives. GammaWorm writes a full '~.gif' copy to each drive root, sets Hidden+System attributes on legitimate folders, and replaces them with LNK shortcuts that carry folder icons and names. The dual-execution LNK runs an mshta.exe javascript: eval that both opens the real folder via explorer and silently launches 'wscript.exe ~.gif //b //e:vbScript'. Decoy LNKs use provocative Ukrainian-language lures (e.g. 'таємно.doc', 'карта обліку.doc', 'фото військовополоненого.jpeg', 'згвалтування.jpeg', 'порно-фото.jpeg'). Propagation recurses to a 4-folder depth.

COMMAND & CONTROL (Dead Drop Resolvers): GammaWorm resolves live C2 through Dead Drop Resolvers rather than hardcoded servers. Hardcoded seed pages live on Telegraph/Teletype and Telegram (graph.org/kyjfkyr-12-06, telegra.ph/f8bfl6sp-01-02, t.me/s/teotori, www.telegram.me/s/oberfarir); the worm pulls these (including via curl.exe), parses embedded URLs/IPs in a five-loop recursive chain, and caches each tier in HKCU\Console\ values (WindowsUpdates/WindowsResponby for the primary C2 domain, WindowsDetect/URLTeletype for Teletype, WindowsTelegra/URLTelegra for Telegraph, IpURL for a direct-IP fallback). Observed staging infrastructure includes Cloudflare Workers subdomains (bold.zsjtn41091.workers.dev), a Cloudflare quick tunnel (efficiency-planes-emotions-fascinating.trycloudflare.com), an operator domain (quitethepastry.ru), and a direct C2 IP (104.194.140.6). This hybrid design enables rapid rotation, hides staging behind Cloudflare, and falls back to direct IPs if cloud services are disrupted.

BACKDOOR LOOP & EXFIL: A continuous loop (28-second sleep) beacons to the resolved C2, encoding host fingerprints (ComputerName, hex drive serial, random strings) into randomized HTTP headers to mimic normal web traffic — a structured User-Agent with rotating separators (::, ##, !!, ??, ==), spoofed Referer values (.gov.ua/.mil.gov.ua/.nato.int/.gov.md), randomized Cookie names/values, varied Accept-Language q-values, and random Content-Length (2916-6966 bytes). On HTTP 200 with no <html> tag the response is Base64-decoded, stripped of CR/'&&' markers, and run via ExecuteGlobal for in-memory execution; on HTTP 404 the response delimiters update the registry C2 configuration. Because every stage can re-profile the host, update config, and fetch fresh payloads, the chain behaves as a stack of redundant backdoors — partial cleanup leaves surviving components able to restore access.

STRATEGIC SIGNIFICANCE: The same Gamaredon tooling has been used to hand access to Turla (FSB Center 16) for Kazuar deployment (ESET, Sept 2025), underscoring that a GammaWorm foothold can be a precursor to higher-tier intrusion. The campaign's combination of fileless VBScript, ADS concealment, USB-borne worming, and cloud-backed DDR C2 substantially raises stealth and durability over earlier Gamaredon frameworks.

MITRE ATT&CK techniques used in TL-2026-0653

Collection

T1005 Data from Local System; T1025 Data from Removable Media

Command and Control

T1008 Fallback Channels; T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1211 Exploitation for Stealth; T1218 System Binary Proxy Execution; T1564 Hide Artifacts

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution

Lateral Movement

T1080 Taint Shared Content

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery

Initial Access

T1091 Replication Through Removable Media; T1566 Phishing

defense-impairment

T1112 Modify Registry

Persistence

T1547 Boot or Logon Autostart Execution

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Affected products and versions in Gamaredon (Russia/FSB) "GammaWorm"

  • RARLAB — WinRAR (Windows)
    Vulnerable versions: <= 7.12
    Fixed in: 7.13
  • RARLAB — UnRAR.dll / WinRAR command-line (Windows)
    Vulnerable versions: <= 7.12
    Fixed in: 7.13
  • Microsoft — Windows (NTFS / Windows Script Host / mshta)
    Vulnerable versions: 10; 11; Server 2016-2022

Remediation for Gamaredon (Russia/FSB) "GammaWorm"

Patches

  • WinRAR 7.13 (fixes CVE-2025-8088) — https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283

Immediate actions

  • Update WinRAR to 7.13 or later to remediate CVE-2025-8088 (no auto-update in WinRAR; manual install required).
  • Block/monitor the listed DDR seed pages and C2 (graph.org/kyjfkyr-12-06, telegra.ph/f8bfl6sp-01-02, t.me/s/teotori, telegram.me/s/oberfarir, bold.zsjtn41091.workers.dev, quitethepastry.ru, *.trycloudflare.com, 104.194.140.6).
  • Hunt for NTFS ADS on user-profile paths (%USERPROFILE%:GTR, %USERPROFILE%:save, %USERPROFILE%:URL, :LNK, :SERVER) and on boot.ini in the profile.
  • Inspect HKCU RunOnce\ExplorerGuard and HKCU\Console\ values (WindowsUpdates, WindowsResponby, WindowsDetect, URLTeletype, WindowsTelegra, URLTelegra, IpURL) and remove.
  • Disable/quarantine rogue scheduled tasks named DiskDiagnosticDataCollector, SilentCleanup, SmartRetry that invoke wscript.exe/mshta.exe against ADS.

Workarounds

  • Until WinRAR is updated, avoid extracting untrusted archives; consider an alternative archiver.
  • Set HKCU\...\Explorer\Advanced Hidden=1/ShowSuperHidden=1/HideFileExt=0 via GPO and monitor for reversion.
  • Block the '@' userinfo URL pattern and HTML-smuggling content at the web proxy.

Longer-term hardening

  • Deploy EDR with behavioral detection for mshta.exe/wscript.exe spawning from LNK and reading from ADS; alert on curl.exe to telegram/telegraph.
  • Restrict or block mshta.exe and wscript.exe execution via WDAC/AppLocker where business needs allow.
  • Enforce removable-media controls and disable AutoRun; flag LNK files that hide folders with Hidden+System attributes.
  • Egress-filter and inspect traffic to Telegraph/Teletype/Telegram, *.workers.dev, and *.trycloudflare.com for DDR abuse.
  • Sweep for downstream Turla/Kazuar activity on any host showing Gamaredon Ptero/Gamma artifacts.

CVEs associated with Gamaredon (Russia/FSB) "GammaWorm"

CVE-2025-8088

Weaknesses (CWE) in Gamaredon (Russia/FSB) "GammaWorm"

CWE-35

Timeline of Gamaredon (Russia/FSB) "GammaWorm"

  • Gamaredon active since at least 2013; attributed by Ukraine's SSU to FSB Center 18 (Center for Information Security), operating from occupied Crimea.
  • Group operated the Pteranodon/Pterodo framework (2016-2021) before transitioning to modular standalone Ptero* and Gamma families.
  • WinRAR path-traversal CVE-2025-8088 disclosed and patched in WinRAR 7.13; discovered by ESET (Cherepanov, Kosinar, Strycek), already exploited in the wild by multiple groups.
  • ESET documents Gamaredon handing access to Turla (FSB Center 16) to deploy Kazuar in Ukraine, confirming Gamaredon footholds as precursors to higher-tier intrusion.
  • Weaponized GammaPhish xHTML/RAR lures dated 09.12.2025 observed (e.g. 1_13_5_1691_09.12.2025.xhtml, 2_14_6_1033_09.12.2025.rar).
  • Sekoia analyzes the Gamma-toolset campaign (GammaPhish/GammaWorm), detailing NTFS-ADS concealment and cloud Dead Drop Resolver C2; campaign assessed ongoing.
  • Public reporting (Cyber Security News, citing Sekoia) details GammaWorm hiding in Windows features and abusing cloud platforms for C2.

Sources cited for Gamaredon (Russia/FSB) "GammaWorm"

Detection coverage for TL-2026-0653

As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0653 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
42 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats