Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)

Gamaredon (Primitive Bear / Shuckworm) APT Profile (TL-2026-1210), also tracked as Gamaredon WinRAR Campaign, is a high-severity tracked threat-actor profile scored CVSS 8.8, first published 2026-07-11. It is attributed to Gamaredon (Russia) with high confidence, affects RARLAB WinRAR (Windows), references 1 CVE (CVE-2025-8088), maps to 50 MITRE ATT&CK techniques (T1005, T1008, T1025), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-1210

Threat ID
TL-2026-1210
Also known as
Gamaredon WinRAR Campaign, Earth Dahu WinRAR Campaign
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
THREAT_ACTOR
First published
2026-07-11
Last reviewed
2026-07-11
Attribution
Gamaredon
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, defense, police - law enforcement, critical infrastructure, military
Target regions
ukraine, bulgaria, latvia, lithuania, poland, uzbekistan, kazakhstan, tajikistan, kyrgyzstan
Detection rules
9
Indicators of compromise
31

Malware and tooling in Gamaredon (Primitive Bear / Shuckworm) APT Profile

Malware and tooling: GammaLoad, GammaPhish, GammaSteel, GammaWipe, GammaWorm, PteroGraphin, PteroLNK, Cloudflare Workers (*.workers.dev), Rclone - S1040, Remcos, Telegram dead-drop resolver, cloudflared

Gamaredon (aka Primitive Bear, Shuckworm, ACTINIUM, Aqua Blizzard, Armageddon, UAC-0010, Trident Ursa), a Russia-aligned APT active since 2013 and widely attributed to Russia's FSB, continues high-tempo espionage against Ukrainian government, defense, law enforcement, and critical infrastructure, with expansion into NATO member states (Bulgaria, Latvia, Lithuania, Poland). Since September 2025 the group has weaponized CVE-2025-8088, a WinRAR NTFS Alternate-Data-Stream path-traversal flaw, to plant GammaPhish/GammaLoad/GammaWorm/GammaSteel payloads via malicious RAR archives disguised as court summonses or defense-ministry documents.

How Gamaredon (Primitive Bear / Shuckworm) APT Profile works

Gamaredon (Primitive Bear, Shuckworm, ACTINIUM, Aqua Blizzard, Armageddon, Blue Otso, BlueAlpha, DEV-0157, G0047, IRON TILDEN, SectorC08, Trident Ursa, UAC-0010, UNC530, Winterflounder) is a Russia-aligned advanced persistent threat group active since at least 2013, widely and publicly attributed to Russia's Federal Security Service (FSB). The group is one of the highest-tempo actors targeting Ukraine, having historically hit 1,500+ systems across Ukrainian government, defense, law enforcement, and critical-infrastructure organizations, and has progressively expanded operations against NATO member states Bulgaria, Latvia, Lithuania, and Poland, as well as Russian-speaking populations in Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan.

The group operates a large custom malware suite built around the 'Gamma*' and 'Ptero*' code families: GammaDrop (VBScript dropper), GammaLoad (VBScript/HTA downloader), GammaSteel (PowerShell/modular infostealer), GammaPhish (HTA payload), GammaWorm (USB/LNK self-propagating worm), GammaWipe/GamaWiper (destructive payload variant), PteroGraphin (PowerShell persistence via malicious Excel add-ins, introduced August 2024), PteroLNK (USB weaponizer), PteroTemplate (Word remote-template injection), PteroScreen (screenshot capture), PteroCookie/PteroSteal/PteroScout (credential harvesting and reconnaissance), PteroPSDoor/PteroVDoor (file collection and exfiltration), PteroPShell (raw TCP reverse shell), and PteroClone (rclone-based exfiltration to cloud storage). The group also fields Android spyware (BoneSpy, PlainGnome) and leverages third-party/open-source tooling including the Remcos commercial RAT, ReVBShell, rclone, cloudflared (Cloudflare Tunnel client, abused from September 2024), and ngrok.

Since at least September 2025, Gamaredon (tracked in this specific WinRAR campaign by some vendors as 'Earth Dahu') has incorporated CVE-2025-8088 — a WinRAR NTFS Alternate Data Stream path-traversal vulnerability affecting versions up to 7.12 — into its intrusion chain. Malicious RAR archives are distributed via spear-phishing, disguised as court summonses, administrative notices, or Ministry of Defense documents. The archive's ADS stream name embeds directory-traversal sequences (e.g. redundant '\Programs\..\Programs\..\Programs\' segments — a Gamaredon-specific quirk that defeats WinRAR's traversal mitigations) so that, on extraction with a vulnerable WinRAR build, a hidden payload is silently written into the victim's Startup folder while a decoy PDF is displayed. This launches an HTA-to-VBScript infection chain: GammaPhish (HTA) retrieves GammaLoad (VBScript downloader), which performs host fingerprinting and registry-based configuration via dead-drop resolvers (DDRs — Telegram channels, telegra.ph, teletype.in) before fetching further VBScript payloads. GammaWorm then establishes scheduled-task persistence and self-propagates via concealed directories on network shares and removable USB media using malicious LNK files; GammaSteel exfiltrates documents matching a hardcoded extension list (.doc, .docx, .xls, .xlsx, .ppt, .pptx, .vsd, .vsdx, .rtf, .odt, .txt, .pdf) plus Signal/Telegram/browser data stores, staged and exfiltrated to attacker infrastructure including AWS S3 buckets and rclone-to-MEGA cloud sync. CVE-2025-8088 exploitation by Gamaredon and other Ukraine-focused intrusion sets continued to produce new exploit samples at least into April 2026, well after WinRAR 7.13 (released 30 July 2025) patched the flaw — underscoring the persistent unpatched-software exposure in Ukrainian environments.

Gamaredon's C2 infrastructure follows a consistent pattern of 'twin' domain registrations (e.g. kosoyed[.]ru + kosoyed[.]online) registered simultaneously through REG.RU using consistent Cloudflare nameservers, backed by VPS providers DigitalOcean, MivoCloud, TimeWeb, and Global Internet Solutions LLC, plus abuse of Cloudflare Workers (*.workers.dev) for staged delivery/beaconing, dynamic DNS (ddnsking[.]com, ddns[.]net), and periodic hijacking of legitimate compromised domains via registrar-account compromise (e.g. joymobile.com[.]ua). GammaLoad implements automatic C2 fallback: if the primary Cloudflare Workers channel returns a response under 75 characters or an HTTP 404, the malware switches to a hardcoded .ru fallback domain.

Gamaredon also functions as an access broker for other Russian state-aligned operators: in January 2025 it breached four machines in Ukraine and handed initial access to the Turla APT, demonstrating coordination between distinct FSB/SVR-aligned units for staged intrusions. On 26 February 2025, the group compromised a Western military mission using an infected removable drive, and in March 2025 it ran a Russian troop-movement lure campaign distributing malicious LNK files.

MITRE ATT&CK techniques used in TL-2026-1210

Collection

T1005 Data from Local System; T1025 Data from Removable Media; T1039 Data from Network Shared Drive; T1074.001 Local Data Staging; T1113 Screen Capture

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1095 Non-Application Layer Protocol; T1102.001 Dead Drop Resolver; T1132 Data Encoding; T1568 Dynamic Resolution; T1572 Protocol Tunneling

Defense Evasion

T1027.006 HTML Smuggling; T1027.011 Fileless Storage; T1027.013 Encrypted/Encoded File; T1036.004 Masquerade Task or Service; T1036.007 Double File Extension; T1218.005 Mshta; T1480.001 Environmental Keying

Persistence

T1037.001 Logon Script (Windows); T1053.005 Scheduled Task; T1137.001 Office Template Macros; T1547.001 Registry Run Keys / Startup Folder

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage

Execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.007 JavaScript; T1106 Native API; T1204.002 Malicious File

Lateral Movement

T1080 Taint Shared Content; T1091 Replication Through Removable Media

Initial Access

T1091 Replication Through Removable Media; T1566.001 Spearphishing Attachment

defense-impairment

T1112 Modify Registry; T1222 File and Directory Permissions Modification

execution

T1203 Exploitation for Client Execution

Impact

T1485 Data Destruction

Discovery

T1518.001 Security Software Discovery

Credential Access

T1539 Steal Web Session Cookie; T1552.002 Credentials in Registry; T1555.003 Credentials from Web Browsers

Resource Development

T1583.001 Domains; T1583.003 Virtual Private Server; T1583.006 Web Services; T1584.001 Domains; T1586.002 Email Accounts; T1587.001 Malware; T1588.002 Tool

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Gamaredon (Primitive Bear / Shuckworm) APT Profile

  • RARLAB — WinRAR (Windows)
    Vulnerable versions: up to 7.12
    Fixed in: 7.13 and later
  • DtSearch — dtSearch Engine
    Vulnerable versions: up to 2023.01
    Fixed in: post-2023.01 patched builds

Remediation for Gamaredon (Primitive Bear / Shuckworm) APT Profile

Patches

  • WinRAR 7.13 (released 2025-07-30) patches CVE-2025-8088

Immediate actions

  • Patch WinRAR to version 7.13 or later on all Windows endpoints to remediate CVE-2025-8088
  • Block execution of mshta.exe and wscript.exe from user Downloads/Temp/Startup paths via application control
  • Block outbound traffic to known Gamaredon dynamic-DNS domains (ddnsking[.]com, ddns[.]net) and dead-drop resolver services where not business-required
  • Alert on new files written to the Startup folder or Run/RunOnce registry keys immediately following archive extraction
  • Disable Office macros and remote template injection (Normal.dotm protection) via GPO

Workarounds

  • Restrict WinRAR/archive-tool usage to a vetted, centrally-updated version via software allowlisting until patched
  • Configure mail gateways to strip or sandbox RAR/ZIP/7z/TAR attachments from external senders

Longer-term hardening

  • Deploy EDR with behavioral detection for LNK-based USB propagation, HTA proxy execution, and PowerShell in-memory execution
  • Implement network segmentation to limit lateral movement via mapped network drives
  • Enforce a vulnerable-software inventory/patch-SLA program for widely-deployed archive utilities
  • Monitor for Cloudflare Tunnel (cloudflared) and ngrok binary execution/installation on endpoints not authorized to use tunneling tools
  • Hunt for rclone execution or MEGA/AWS S3 exfiltration patterns on hosts with no legitimate cloud-sync business need

CVEs associated with Gamaredon (Primitive Bear / Shuckworm) APT Profile

CVE-2025-8088

Weaknesses (CWE) in Gamaredon (Primitive Bear / Shuckworm) APT Profile

CWE-35

Timeline of Gamaredon (Primitive Bear / Shuckworm) APT Profile

  • Gamaredon (Primitive Bear/Shuckworm) begins operations targeting Ukrainian institutions, later attributed to Russia's FSB.
  • BoneSpy Android spyware deployment accompanies a wave of 5,000+ attacks against Ukrainian authorities.
  • Phishing operation deploys Giddome and Pterodo malware families against Ukrainian targets.
  • Unsuccessful breach attempt against a NATO member state petroleum company.
  • GammaLoad/GammaSteel spear-phishing campaigns mark the start of sustained NATO member state targeting.
  • PteroGraphin PowerShell persistence tool introduced, abusing malicious Excel add-ins.
  • Group begins abusing Cloudflare Tunnels (cloudflared) in attacks against Ukraine and NATO members Bulgaria, Latvia, Lithuania, and Poland.
  • BoneSpy/PlainGnome Android spyware deployed against former Soviet state populations.
  • Gamaredon breaches four machines in Ukraine and hands off initial access to the Turla APT.
  • Western military mission compromised via an infected removable USB drive.
  • Campaign distributing malicious LNK files using Russian troop-movement lures.
  • WinRAR 7.13 released, patching CVE-2025-8088.
  • Gamaredon (tracked by some vendors as Earth Dahu) incorporates CVE-2025-8088 into an HTA-to-VBScript infection chain delivering espionage modules.
  • Google Threat Analysis Group and Google Cloud publicly warn of active, multi-actor exploitation of CVE-2025-8088, including by Gamaredon.
  • Gamaredon and other Ukraine-focused intrusion sets continue producing new CVE-2025-8088 exploit samples, nearly a year after the patch was released.
  • Sekoia and other vendors detail a modular Gamaredon WinRAR campaign delivering GammaPhish, GammaLoad, GammaWorm, and GammaSteel with AWS S3/MEGA exfiltration.
  • Reporting describes Gamaredon's first observed destructive payload variant (GammaWipe/GamaWiper) in the WinRAR campaign.

Sources cited for Gamaredon (Primitive Bear / Shuckworm) APT Profile

Threats related to Gamaredon (Primitive Bear / Shuckworm) APT Profile

Detection coverage for TL-2026-1210

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1210 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats