Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088 — Threadlinqs Intelligence
As of 2026-06-29, Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088 is a high-severity vulnerability threat attributed to Gamaredon (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1216 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Gamaredon · Russia · ESPIONAGE
Russian APT group Gamaredon ran 35 spear-phishing campaigns against Ukrainian governmental and military institutions throughout 2025, reviving the dormant PteroSetup VBScript weaponizer and expanding
ESET Research documented a comprehensive 2025 retrospective of Gamaredon (aka Armageddon, Shuckworm, UAC-0010, Trident Ursa, Iron Tilden), a Russia-aligned APT attributed by Ukraine's Security Service (SSU) to the 18th Center of Information Security of Russia's FSB, believed to operate out of occupied Crimea. Across 35 distinct spear-phishing campaigns during 2025, the group exclusively targeted Ukrainian governmental and military institutions in pursuit of sustained cyberespionage and data exfiltration supporting Russian interests in the war against Ukraine.
After an operational pause in January 2025 the group spent Q1 building new delivery tooling, releasing five of six brand-new PowerShell/VBScript tools (PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy) that joined and updated the existing Ptero malware family (PteroLNK, PteroPSLoad, PteroPSDoor, PteroVDoor, PteroBox, PteroSand, PteroPaste). Notably, Gamaredon resurrected PteroSetup, a VBScript weaponizer first seen in January 2021 that had been dormant for years; the revived version scans fixed, removable, and network drives for installer-like executables and replaces them with malicious self-extracting 7z SFX archives bundling the legitimate installer alongside a malicious VBScript downloader, so that execution launches both the expected application and the malicious payload.
The group's second half of 2025 saw a marked escalation in campaign frequency and scale, delivered via malicious archive attachments and XHTML files using HTML smuggling (T1027.006), spear-phishing attachments (T1566.002), and malicious LNK files enabling lateral movement across USB drives and mapped network shares (T1091/T1570). Beginning September 26, 2025, Gamaredon began abusing CVE-2025-8088 -- a critical path-traversal vulnerability in the Windows build of WinRAR (patched in version 7.13, released July 30, 2025) -- to smuggle a malicious HTA downloader directly into the victim's Startup folder via crafted Alternate Data Stream (ADS) paths inside RAR archives, achieving persistence through automatic execution at next logon (T1547.001).
A defining feature of Gamaredon's 2025 tradecraft was heavy reliance on legitimate third-party cloud and developer infrastructure to hide back-end C2 and complicate takedown/attribution: Cloudflare Tunnels (trycloudflare.com) and Workers (workers.dev), Microsoft DevTunnels (devtunnels.ms), Loophole (loophole.site), No-IP DDNS, Clever Cloud (cleverapps.io), and Supabase (supabase.co) were used for C2 relay, while Telegram/Telegra.ph, Teletype, Rentry.co, Write.as, Dropbox, GoFile, DEV Community, Mastodon, Lesma, Nopaste.net, and Paste.ee served as dead-drop resolvers for payload and configuration retrieval (PteroOdd fetches payloads via the Telegra.ph API; PteroEffigy resolves C2 details via GoFile). Data exfiltration progressively shifted to S3-compatible object storage providers -- Wasabi, then Tebi, then Intercolo (established as the primary exfiltration destination by December 2025) -- alongside continued use of Dropbox via PteroBox and rclone (T1537).
ESET also documented early-2025 operational collaboration between Gamaredon and the Turla APT group (also FSB-linked), with the PteroOdd tool specifically associated with the joint activity. ESET researchers observed that tool-update cadence paused around major Russian and Crimean holidays, consistent with operators being government-affiliated employees working standard schedules rather than a criminal enterprise.
CVE-2025-8088 itself is a high-severity (CVSS 3.1: 8.8) path traversal vulnerability in RARLAB WinRAR (CWE-35) affecting the Windows version of WinRAR 7.12 and earlier plus the UnRAR.dll/UnRAR source components (non-Windows platforms unaffected); dtSearch versions prior to 2023.01, which bundles vulnerable UnRAR code, are also affected. Crafted archives abuse ADS path traversal (..\ sequences) to write attacker-controlled files outside the intended extraction directory, into locations such as
Weaknesses (CWE)
CWE-35, CWE-22
Target sectors: government administration, military, defense
Target regions: ukraine, Crimea
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2025-8088, T1589, T1583, T1587, T1566, T1091, T1059, T1059, T1204, T1547, T1027