Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)
Gamaredon (Primitive Bear / Shuckworm) APT Profile (TL-2026-1210), also tracked as Gamaredon WinRAR Campaign, is a high-severity tracked threat-actor profile scored CVSS 8.8, first published 2026-07-11. It is attributed to Gamaredon (Russia) with high confidence, affects RARLAB WinRAR (Windows), references 1 CVE (CVE-2025-8088), maps to 50 MITRE ATT&CK techniques (T1005, T1008, T1025), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-1210
- Threat ID
- TL-2026-1210
- Also known as
- Gamaredon WinRAR Campaign, Earth Dahu WinRAR Campaign
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- THREAT_ACTOR
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution
- Gamaredon
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, police - law enforcement, critical infrastructure, military
- Target regions
- ukraine, bulgaria, latvia, lithuania, poland, uzbekistan, kazakhstan, tajikistan, kyrgyzstan
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in Gamaredon (Primitive Bear / Shuckworm) APT Profile
Malware and tooling: GammaLoad, GammaPhish, GammaSteel, GammaWipe, GammaWorm, PteroGraphin, PteroLNK, Cloudflare Workers (*.workers.dev), Rclone - S1040, Remcos, Telegram dead-drop resolver, cloudflared
Gamaredon (aka Primitive Bear, Shuckworm, ACTINIUM, Aqua Blizzard, Armageddon, UAC-0010, Trident Ursa), a Russia-aligned APT active since 2013 and widely attributed to Russia's FSB, continues high-tempo espionage against Ukrainian government, defense, law enforcement, and critical infrastructure, with expansion into NATO member states (Bulgaria, Latvia, Lithuania, Poland). Since September 2025 the group has weaponized CVE-2025-8088, a WinRAR NTFS Alternate-Data-Stream path-traversal flaw, to plant GammaPhish/GammaLoad/GammaWorm/GammaSteel payloads via malicious RAR archives disguised as court summonses or defense-ministry documents.
How Gamaredon (Primitive Bear / Shuckworm) APT Profile works
Gamaredon (Primitive Bear, Shuckworm, ACTINIUM, Aqua Blizzard, Armageddon, Blue Otso, BlueAlpha, DEV-0157, G0047, IRON TILDEN, SectorC08, Trident Ursa, UAC-0010, UNC530, Winterflounder) is a Russia-aligned advanced persistent threat group active since at least 2013, widely and publicly attributed to Russia's Federal Security Service (FSB). The group is one of the highest-tempo actors targeting Ukraine, having historically hit 1,500+ systems across Ukrainian government, defense, law enforcement, and critical-infrastructure organizations, and has progressively expanded operations against NATO member states Bulgaria, Latvia, Lithuania, and Poland, as well as Russian-speaking populations in Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan.
The group operates a large custom malware suite built around the 'Gamma*' and 'Ptero*' code families: GammaDrop (VBScript dropper), GammaLoad (VBScript/HTA downloader), GammaSteel (PowerShell/modular infostealer), GammaPhish (HTA payload), GammaWorm (USB/LNK self-propagating worm), GammaWipe/GamaWiper (destructive payload variant), PteroGraphin (PowerShell persistence via malicious Excel add-ins, introduced August 2024), PteroLNK (USB weaponizer), PteroTemplate (Word remote-template injection), PteroScreen (screenshot capture), PteroCookie/PteroSteal/PteroScout (credential harvesting and reconnaissance), PteroPSDoor/PteroVDoor (file collection and exfiltration), PteroPShell (raw TCP reverse shell), and PteroClone (rclone-based exfiltration to cloud storage). The group also fields Android spyware (BoneSpy, PlainGnome) and leverages third-party/open-source tooling including the Remcos commercial RAT, ReVBShell, rclone, cloudflared (Cloudflare Tunnel client, abused from September 2024), and ngrok.
Since at least September 2025, Gamaredon (tracked in this specific WinRAR campaign by some vendors as 'Earth Dahu') has incorporated CVE-2025-8088 — a WinRAR NTFS Alternate Data Stream path-traversal vulnerability affecting versions up to 7.12 — into its intrusion chain. Malicious RAR archives are distributed via spear-phishing, disguised as court summonses, administrative notices, or Ministry of Defense documents. The archive's ADS stream name embeds directory-traversal sequences (e.g. redundant '\Programs\..\Programs\..\Programs\' segments — a Gamaredon-specific quirk that defeats WinRAR's traversal mitigations) so that, on extraction with a vulnerable WinRAR build, a hidden payload is silently written into the victim's Startup folder while a decoy PDF is displayed. This launches an HTA-to-VBScript infection chain: GammaPhish (HTA) retrieves GammaLoad (VBScript downloader), which performs host fingerprinting and registry-based configuration via dead-drop resolvers (DDRs — Telegram channels, telegra.ph, teletype.in) before fetching further VBScript payloads. GammaWorm then establishes scheduled-task persistence and self-propagates via concealed directories on network shares and removable USB media using malicious LNK files; GammaSteel exfiltrates documents matching a hardcoded extension list (.doc, .docx, .xls, .xlsx, .ppt, .pptx, .vsd, .vsdx, .rtf, .odt, .txt, .pdf) plus Signal/Telegram/browser data stores, staged and exfiltrated to attacker infrastructure including AWS S3 buckets and rclone-to-MEGA cloud sync. CVE-2025-8088 exploitation by Gamaredon and other Ukraine-focused intrusion sets continued to produce new exploit samples at least into April 2026, well after WinRAR 7.13 (released 30 July 2025) patched the flaw — underscoring the persistent unpatched-software exposure in Ukrainian environments.
Gamaredon's C2 infrastructure follows a consistent pattern of 'twin' domain registrations (e.g. kosoyed[.]ru + kosoyed[.]online) registered simultaneously through REG.RU using consistent Cloudflare nameservers, backed by VPS providers DigitalOcean, MivoCloud, TimeWeb, and Global Internet Solutions LLC, plus abuse of Cloudflare Workers (*.workers.dev) for staged delivery/beaconing, dynamic DNS (ddnsking[.]com, ddns[.]net), and periodic hijacking of legitimate compromised domains via registrar-account compromise (e.g. joymobile.com[.]ua). GammaLoad implements automatic C2 fallback: if the primary Cloudflare Workers channel returns a response under 75 characters or an HTTP 404, the malware switches to a hardcoded .ru fallback domain.
Gamaredon also functions as an access broker for other Russian state-aligned operators: in January 2025 it breached four machines in Ukraine and handed initial access to the Turla APT, demonstrating coordination between distinct FSB/SVR-aligned units for staged intrusions. On 26 February 2025, the group compromised a Western military mission using an infected removable drive, and in March 2025 it ran a Russian troop-movement lure campaign distributing malicious LNK files.
MITRE ATT&CK techniques used in TL-2026-1210
Collection
T1005 Data from Local System; T1025 Data from Removable Media; T1039 Data from Network Shared Drive; T1074.001 Local Data Staging; T1113 Screen Capture
Command and Control
T1008 Fallback Channels; T1071.001 Web Protocols; T1095 Non-Application Layer Protocol; T1102.001 Dead Drop Resolver; T1132 Data Encoding; T1568 Dynamic Resolution; T1572 Protocol Tunneling
Defense Evasion
T1027.006 HTML Smuggling; T1027.011 Fileless Storage; T1027.013 Encrypted/Encoded File; T1036.004 Masquerade Task or Service; T1036.007 Double File Extension; T1218.005 Mshta; T1480.001 Environmental Keying
Persistence
T1037.001 Logon Script (Windows); T1053.005 Scheduled Task; T1137.001 Office Template Macros; T1547.001 Registry Run Keys / Startup Folder
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.007 JavaScript; T1106 Native API; T1204.002 Malicious File
Lateral Movement
T1080 Taint Shared Content; T1091 Replication Through Removable Media
Initial Access
T1091 Replication Through Removable Media; T1566.001 Spearphishing Attachment
defense-impairment
T1112 Modify Registry; T1222 File and Directory Permissions Modification
execution
T1203 Exploitation for Client Execution
Impact
Discovery
T1518.001 Security Software Discovery
Credential Access
T1539 Steal Web Session Cookie; T1552.002 Credentials in Registry; T1555.003 Credentials from Web Browsers
Resource Development
T1583.001 Domains; T1583.003 Virtual Private Server; T1583.006 Web Services; T1584.001 Domains; T1586.002 Email Accounts; T1587.001 Malware; T1588.002 Tool
Reconnaissance
Affected products and versions in Gamaredon (Primitive Bear / Shuckworm) APT Profile
- RARLAB — WinRAR (Windows)
Vulnerable versions: up to 7.12
Fixed in: 7.13 and later - DtSearch — dtSearch Engine
Vulnerable versions: up to 2023.01
Fixed in: post-2023.01 patched builds
Remediation for Gamaredon (Primitive Bear / Shuckworm) APT Profile
Patches
- WinRAR 7.13 (released 2025-07-30) patches CVE-2025-8088
Immediate actions
- Patch WinRAR to version 7.13 or later on all Windows endpoints to remediate CVE-2025-8088
- Block execution of mshta.exe and wscript.exe from user Downloads/Temp/Startup paths via application control
- Block outbound traffic to known Gamaredon dynamic-DNS domains (ddnsking[.]com, ddns[.]net) and dead-drop resolver services where not business-required
- Alert on new files written to the Startup folder or Run/RunOnce registry keys immediately following archive extraction
- Disable Office macros and remote template injection (Normal.dotm protection) via GPO
Workarounds
- Restrict WinRAR/archive-tool usage to a vetted, centrally-updated version via software allowlisting until patched
- Configure mail gateways to strip or sandbox RAR/ZIP/7z/TAR attachments from external senders
Longer-term hardening
- Deploy EDR with behavioral detection for LNK-based USB propagation, HTA proxy execution, and PowerShell in-memory execution
- Implement network segmentation to limit lateral movement via mapped network drives
- Enforce a vulnerable-software inventory/patch-SLA program for widely-deployed archive utilities
- Monitor for Cloudflare Tunnel (cloudflared) and ngrok binary execution/installation on endpoints not authorized to use tunneling tools
- Hunt for rclone execution or MEGA/AWS S3 exfiltration patterns on hosts with no legitimate cloud-sync business need
CVEs associated with Gamaredon (Primitive Bear / Shuckworm) APT Profile
Weaknesses (CWE) in Gamaredon (Primitive Bear / Shuckworm) APT Profile
CWE-35
Timeline of Gamaredon (Primitive Bear / Shuckworm) APT Profile
- Gamaredon (Primitive Bear/Shuckworm) begins operations targeting Ukrainian institutions, later attributed to Russia's FSB.
- BoneSpy Android spyware deployment accompanies a wave of 5,000+ attacks against Ukrainian authorities.
- Phishing operation deploys Giddome and Pterodo malware families against Ukrainian targets.
- Unsuccessful breach attempt against a NATO member state petroleum company.
- GammaLoad/GammaSteel spear-phishing campaigns mark the start of sustained NATO member state targeting.
- PteroGraphin PowerShell persistence tool introduced, abusing malicious Excel add-ins.
- Group begins abusing Cloudflare Tunnels (cloudflared) in attacks against Ukraine and NATO members Bulgaria, Latvia, Lithuania, and Poland.
- BoneSpy/PlainGnome Android spyware deployed against former Soviet state populations.
- Gamaredon breaches four machines in Ukraine and hands off initial access to the Turla APT.
- Western military mission compromised via an infected removable USB drive.
- Campaign distributing malicious LNK files using Russian troop-movement lures.
- WinRAR 7.13 released, patching CVE-2025-8088.
- Gamaredon (tracked by some vendors as Earth Dahu) incorporates CVE-2025-8088 into an HTA-to-VBScript infection chain delivering espionage modules.
- Google Threat Analysis Group and Google Cloud publicly warn of active, multi-actor exploitation of CVE-2025-8088, including by Gamaredon.
- Gamaredon and other Ukraine-focused intrusion sets continue producing new CVE-2025-8088 exploit samples, nearly a year after the patch was released.
- Sekoia and other vendors detail a modular Gamaredon WinRAR campaign delivering GammaPhish, GammaLoad, GammaWorm, and GammaSteel with AWS S3/MEGA exfiltration.
- Reporting describes Gamaredon's first observed destructive payload variant (GammaWipe/GamaWiper) in the WinRAR campaign.
Sources cited for Gamaredon (Primitive Bear / Shuckworm) APT Profile
- Gamaredon / Primitive Bear APT Profile and MITRE ATT&CK Breakdown
- Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
- Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088
- Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
- CVE-2025-8088 Detail
- WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
- Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
- Russian Hackers Gamaredon Weaponize WinRAR Flaw for First Destructive Strike
- Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
- CVE-2025-8088 Detail - NVD
- Gamaredon Exploits WinRAR Path Traversal (CVE-2025-8088) to Deploy Modular Malware Chain Against Ukrainian Targets
Threats related to Gamaredon (Primitive Bear / Shuckworm) APT Profile
- Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains
- Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088
Detection coverage for TL-2026-1210
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1210 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.