Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR) — Threadlinqs Intelligence
As of 2026-07-11, Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR) is a high-severity threat actor threat attributed to Gamaredon (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1210 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: THREAT_ACTOR
Attribution: Gamaredon · Russia · ESPIONAGE
Gamaredon (aka Primitive Bear, Shuckworm, ACTINIUM, Aqua Blizzard, Armageddon, UAC-0010, Trident Ursa), a Russia-aligned APT active since 2013 and widely attributed to Russia's FSB, continues
Gamaredon (Primitive Bear, Shuckworm, ACTINIUM, Aqua Blizzard, Armageddon, Blue Otso, BlueAlpha, DEV-0157, G0047, IRON TILDEN, SectorC08, Trident Ursa, UAC-0010, UNC530, Winterflounder) is a Russia-aligned advanced persistent threat group active since at least 2013, widely and publicly attributed to Russia's Federal Security Service (FSB). The group is one of the highest-tempo actors targeting Ukraine, having historically hit 1,500+ systems across Ukrainian government, defense, law enforcement, and critical-infrastructure organizations, and has progressively expanded operations against NATO member states Bulgaria, Latvia, Lithuania, and Poland, as well as Russian-speaking populations in Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan.
The group operates a large custom malware suite built around the 'Gamma*' and 'Ptero*' code families: GammaDrop (VBScript dropper), GammaLoad (VBScript/HTA downloader), GammaSteel (PowerShell/modular infostealer), GammaPhish (HTA payload), GammaWorm (USB/LNK self-propagating worm), GammaWipe/GamaWiper (destructive payload variant), PteroGraphin (PowerShell persistence via malicious Excel add-ins, introduced August 2024), PteroLNK (USB weaponizer), PteroTemplate (Word remote-template injection), PteroScreen (screenshot capture), PteroCookie/PteroSteal/PteroScout (credential harvesting and reconnaissance), PteroPSDoor/PteroVDoor (file collection and exfiltration), PteroPShell (raw TCP reverse shell), and PteroClone (rclone-based exfiltration to cloud storage). The group also fields Android spyware (BoneSpy, PlainGnome) and leverages third-party/open-source tooling including the Remcos commercial RAT, ReVBShell, rclone, cloudflared (Cloudflare Tunnel client, abused from September 2024), and ngrok.
Since at least September 2025, Gamaredon (tracked in this specific WinRAR campaign by some vendors as 'Earth Dahu') has incorporated CVE-2025-8088 — a WinRAR NTFS Alternate Data Stream path-traversal vulnerability affecting versions up to 7.12 — into its intrusion chain. Malicious RAR archives are distributed via spear-phishing, disguised as court summonses, administrative notices, or Ministry of Defense documents. The archive's ADS stream name embeds directory-traversal sequences (e.g. redundant '\Programs\..\Programs\..\Programs\' segments — a Gamaredon-specific quirk that defeats WinRAR's traversal mitigations) so that, on extraction with a vulnerable WinRAR build, a hidden payload is silently written into the victim's Startup folder while a decoy PDF is displayed. This launches an HTA-to-VBScript infection chain: GammaPhish (HTA) retrieves GammaLoad (VBScript downloader), which performs host fingerprinting and registry-based configuration via dead-drop resolvers (DDRs — Telegram channels, telegra.ph, teletype.in) before fetching further VBScript payloads. GammaWorm then establishes scheduled-task persistence and self-propagates via concealed directories on network shares and removable USB media using malicious LNK files; GammaSteel exfiltrates documents matching a hardcoded extension list (.doc, .docx, .xls, .xlsx, .ppt, .pptx, .vsd, .vsdx, .rtf, .odt, .txt, .pdf) plus Signal/Telegram/browser data stores, staged and exfiltrated to attacker infrastructure including AWS S3 buckets and rclone-to-MEGA cloud sync. CVE-2025-8088 exploitation by Gamaredon and other Ukraine-focused intrusion sets continued to produce new exploit samples at least into April 2026, well after WinRAR 7.13 (released 30 July 2025) patched the flaw — underscoring the persistent unpatched-software exposure in Ukrainian environments.
Gamaredon's C2 infrastructure follows a consistent pattern of 'twin' domain registrations (e.g. kosoyed[.]ru + kosoyed[.]online) registered simultaneously through REG.RU using consistent Cloudflare nameservers, backed by VPS providers DigitalOcean, MivoCloud, TimeWeb, and Global Internet Solutions LLC, plus abuse of Cloudflare Workers (*.workers.dev) for staged delivery/beaconing, dynamic DNS (ddnski
Target sectors: government administration, defense, police - law enforcement, critical infrastructure, military
Target regions: ukraine, bulgaria, latvia, lithuania, poland, uzbekistan, kazakhstan, tajikistan, kyrgyzstan
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_ACTOR, HIGH, threat intelligence, cybersecurity, CVE-2025-8088, T1589, T1583.001, T1583.003, T1583.006, T1584.001, T1586.002, T1587.001, T1588.002, T1091, T1566.001