AUTO-UPDATED

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

The Russian state-sponsored hacking group Gamaredon is actively exploiting a WinRAR vulnerability to deploy sophisticated malware families, including GammaWorm and GammaSteel, for data theft and long-term espionage operations.

Key Points

  • Gamaredon is weaponizing CVE-2025-8088, a path traversal flaw in WinRAR, to deliver the GammaPhish HTML Application payload.
  • The infection chain utilizes GammaLoad VBScript downloaders to fetch modular malware, including the GammaWorm worm and GammaSteel information stealer.
  • GammaWorm uses Telegram channels for command-and-control resolution and NTFS Alternate Data Streams to conceal malicious modules on infected systems.
  • Stolen data is exfiltrated to Amazon Web Services S3 buckets or secondary attacker-controlled servers to ensure persistent access.
  • The group, linked to Russia's Federal Security Service (FSB), primarily targets Ukrainian government, military, and critical infrastructure entities.

Why it Matters

This campaign demonstrates how threat actors leverage legitimate platforms like Telegram and cloud storage to blend malicious traffic with standard network activity. The modular design of these tools allows attackers to adapt quickly, posing a significant, ongoing risk to organizations that rely on common file-archiving software.
Internet Published by info@thehackernews.com (The Hacker News)
Read original