# Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access

> Gamaredon, the FSB Center 18 espionage group, is running an ongoing campaign against Ukrainian government, military, and critical-infrastructure networks using a reorganized modular 'Gamma' toolset (GammaPhish, GammaLoad, GammaWorm, GammaSteel). Initial access uses weaponized xHTML lures that HTML-smuggle a malicious RAR exploiting WinRAR path-traversal CVE-2025-8088 to drop an HTA into the Windows Startup folder. GammaWorm is a 20,000-line VBScript that hides almost entirely inside NTFS Alternate Data Streams, persists via a RunOnce key and three scheduled tasks executing from hidden streams, worms across USB/network drives via malicious LNK shortcuts run through mshta.exe/wscript.exe, and uses Dead Drop Resolvers on Telegraph/Teletype/Telegram, Cloudflare Workers, and Cloudflare tunnels for resilient, rotating command-and-control.

- **Published:** 2026-06-02T00:00:00Z
- **Last reviewed:** 2026-06-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0653
- **ID:** TL-2026-0653
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Gamaredon (Russia)
- **Detections:** 9 · **IOCs:** 42 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-8088

## Description

Gamaredon (FSB Center 18 for Information Security, operating from occupied Crimea; attributed by the Security Service of Ukraine) has reorganized its long-running Ukraine espionage arsenal into a modular 'Gamma' ecosystem with dedicated components for phishing (GammaPhish), staging (GammaLoad), worm-like propagation (GammaWorm), and data theft (GammaSteel). Sekoia analyzed the campaign in January 2026; it remains active and is the successor to the group's earlier Pteranodon/Pterodo frameworks (2016-2021) and the Ptero* tool family (PteroLNK, PteroOdd, PteroPaste, PteroGraphin).

INITIAL ACCESS (GammaPhish): The chain begins with a weaponized xHTML file (e.g. 1_13_5_1691_09.12.2025.xhtml) that displays a fake 'DOCUMENT DOWNLOADED' message while beaconing a tracking pixel to a Supabase Edge Function. A JavaScript OnError handler performs HTML smuggling — reconstructing a Base64-embedded RAR archive (2_14_6_1033_09.12.2025.rar) only for Windows User-Agents. The RAR abuses WinRAR path-traversal CVE-2025-8088 (CWE-35), carrying a decoy PDF plus an HTA whose extraction path traverses (..\..\..\..\..\..\) into the per-user Startup folder (AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2_14_6_1033_09.12.2025.HTA), guaranteeing execution at next logon. The HTA launches mshta.exe against a Supabase-hosted URL crafted with an '@' userinfo trick (hxxps://www.bbc.com@<supabase host>/...capture.pdf) to masquerade as a benign domain.

GammaWorm (PROPAGATION & PERSISTENCE): The core implant is a single VBScript of more than 20,000 lines (~90% junk/obfuscation) delivered as '~.gif' and assembled in memory via ExecuteGlobal. It hides its body in NTFS Alternate Data Streams: a primary clone at %USERPROFILE%:GTR, a fallback at %USERPROFILE%\boot.ini, and a killswitch stream %USERPROFILE%:save (activates if it exceeds 100 bytes). Persistence is layered: a RunOnce value HKCU\...\RunOnce\ExplorerGuard relaunches wscript.exe against the ADS copy, and three scheduled tasks masquerading as Windows maintenance jobs — DiskDiagnosticDataCollector (7 min; reads ADS :URL for DDR C2 resolution), SilentCleanup (7 min; reads ADS :LNK for USB/network propagation), and SmartRetry (10 min; reads ADS :SERVER for a DDR clone) — execute code directly from the hidden streams. The worm also tampers with Explorer\Advanced settings (Hidden=0x2, ShowSuperHidden=0x0, HideFileExt=0x1) to conceal files and extensions.

Worming: A WMI query (select * from win32_logicaldisk where mediatype=null) enumerates fixed network/USB drives. GammaWorm writes a full '~.gif' copy to each drive root, sets Hidden+System attributes on legitimate folders, and replaces them with LNK shortcuts that carry folder icons and names. The dual-execution LNK runs an mshta.exe javascript: eval that both opens the real folder via explorer and silently launches 'wscript.exe ~.gif //b //e:vbScript'. Decoy LNKs use provocative Ukrainian-language lures (e.g. 'таємно.doc', 'карта обліку.doc', 'фото військовополоненого.jpeg', 'згвалтування.jpeg', 'порно-фото.jpeg'). Propagation recurses to a 4-folder depth.

COMMAND & CONTROL (Dead Drop Resolvers): GammaWorm resolves live C2 through Dead Drop Resolvers rather than hardcoded servers. Hardcoded seed pages live on Telegraph/Teletype and Telegram (graph.org/kyjfkyr-12-06, telegra.ph/f8bfl6sp-01-02, t.me/s/teotori, www.telegram.me/s/oberfarir); the worm pulls these (including via curl.exe), parses embedded URLs/IPs in a five-loop recursive chain, and caches each tier in HKCU\Console\ values (WindowsUpdates/WindowsResponby for the primary C2 domain, WindowsDetect/URLTeletype for Teletype, WindowsTelegra/URLTelegra for Telegraph, IpURL for a direct-IP fallback). Observed staging infrastructure includes Cloudflare Workers subdomains (bold.zsjtn41091.workers.dev), a Cloudflare quick tunnel (efficiency-planes-emotions-fascinating.trycloudflare.com), an operator domain (quitethepastry.ru), and a direct C2 IP (104.194.140.6). This hybrid design enables rapid rotation, hides staging behind Cloudflare, and falls back to direct IPs if cloud services are disrupted.

BACKDOOR LOOP & EXFIL: A continuous loop (28-second sleep) beacons to the resolved C2, encoding host fingerprints (ComputerName, hex drive serial, random strings) into randomized HTTP headers to mimic normal web traffic — a structured User-Agent with rotating separators (::, ##, !!, ??, ==), spoofed Referer values (.gov.ua/.mil.gov.ua/.nato.int/.gov.md), randomized Cookie names/values, varied Accept-Language q-values, and random Content-Length (2916-6966 bytes). On HTTP 200 with no <html> tag the response is Base64-decoded, stripped of CR/'&&' markers, and run via ExecuteGlobal for in-memory execution; on HTTP 404 the response delimiters update the registry C2 configuration. Because every stage can re-profile the host, update config, and fetch fresh payloads, the chain behaves as a stack of redundant backdoors — partial cleanup leaves surviving components able to restore access.

STRATEGIC SIGNIFICANCE: The same Gamaredon tooling has been used to hand access to Turla (FSB Center 16) for Kazuar deployment (ESET, Sept 2025), underscoring that a GammaWorm foothold can be a precursor to higher-tier intrusion. The campaign's combination of fileless VBScript, ADS concealment, USB-borne worming, and cloud-backed DDR C2 substantially raises stealth and durability over earlier Gamaredon frameworks.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1091 Replication Through Removable Media
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1047 Windows Management Instrumentation
- T1547 Boot or Logon Autostart Execution
- T1564 Hide Artifacts
- T1218 System Binary Proxy Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1112 Modify Registry
- T1211 Exploitation for Stealth
- T1082 System Information Discovery
- T1120 Peripheral Device Discovery
- T1083 File and Directory Discovery
- T1080 Taint Shared Content
- T1005 Data from Local System
- T1025 Data from Removable Media
- T1102 Web Service
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1008 Fallback Channels
- T1041 Exfiltration Over C2 Channel

## Sources

- [Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2](https://cybersecuritynews.com/gamaredon-apt-hides-malware-in-windows-c2/)
- [FSB's matryoshka #1/3: Inside Gamaredon Cyber Operations (GammaPhish & GammaWorm)](https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/)
- [Gamaredon X Turla collab — FSB groups collaborate to deploy Kazuar in Ukraine](https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/)
- [NVD — CVE-2025-8088 (WinRAR path traversal, exploited in the wild)](https://nvd.nist.gov/vuln/detail/CVE-2025-8088)
- [CISA Known Exploited Vulnerabilities — CVE-2025-8088](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088)
- [WinRAR 7.13 release advisory (fixes CVE-2025-8088)](https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283)
- [ESET — Update WinRAR tools now: RomCom and others exploiting CVE-2025-8088 zero-day](https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/)
- [ESET — Gamaredon in 2024 (white paper)](https://web-assets.esetstatic.com/wls/en/papers/white-papers/gamaredon-in-2024.pdf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0653
