The Russian state-sponsored hacking group Gamaredon is actively exploiting a WinRAR vulnerability to deploy sophisticated malware families, including GammaWorm and GammaSteel, for data theft and long-term espionage operations.
Key Points
- Gamaredon is weaponizing CVE-2025-8088, a path traversal flaw in WinRAR, to deliver the GammaPhish HTML Application payload.
- The infection chain utilizes GammaLoad VBScript downloaders to fetch modular malware, including the GammaWorm worm and GammaSteel information stealer.
- GammaWorm uses Telegram channels for command-and-control resolution and NTFS Alternate Data Streams to conceal malicious modules on infected systems.
- Stolen data is exfiltrated to Amazon Web Services S3 buckets or secondary attacker-controlled servers to ensure persistent access.
- The group, linked to Russia's Federal Security Service (FSB), primarily targets Ukrainian government, military, and critical infrastructure entities.