Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
Gamaredon is abusing a WinRAR flaw to launch a malware chain that delivers a worm and an info-stealer against Ukrainian targets.
Intelligence analysis by GPT-5.4 Mini

Sekoia says the Russian-backed Gamaredon group is using WinRAR CVE-2025-8088 to start a multi-stage chain that drops GammaWorm and GammaSteel. The setup is built for persistence, stealth, and theft, with Telegram, scheduled tasks, ADS, and cloud storage all in the mix.
A hacker group is using a broken locker in a popular file tool to sneak in tiny programs that can spread like a bug, steal files, and hide on computers. It is like slipping a secret note inside a package, then using that note to open more doors later.
Analysis
What happened
Sekoia says the Russian hacking group Gamaredon is exploiting a WinRAR path traversal flaw, CVE-2025-8088, to deliver a staged payload chain against Ukraine. The chain starts with an HTML Application payload called GammaPhish, which retrieves a VBScript downloader named GammaLoad.
How the chain works
According to Sekoia, GammaLoad is used to fetch and execute arbitrary VBScript payloads from command-and-control infrastructure. One of those payloads is GammaWorm, a VBScript worm that establishes persistence with scheduled tasks, hides legitimate directories in network shares and USB drives, and replaces them with malicious Windows Shortcut files. The worm then pulls code from a C2 server for execution.
GammaWorm also uses a public Telegram channel as part of its C2 resolution process, making the traffic easier to blend in with normal activity. It further hides core modules using NTFS Alternate Data Streams.
Another payload delivered through GammaLoad is GammaSteel, a modular information stealer that targets files with specific extensions and exfiltrates them to an Amazon Web Services S3 bucket, with an attacker-controlled server as fallback.
Broader context
Sekoia says the infection chain could also support other malware families, including GammaWipe, depending on the operators' goals. The firm says the exact route for GammaWorm is still unclear: it may be dropped by GammaLoad or introduced separately through a weaponized USB drive. The company also assesses with high confidence that GammaPhish is meant to deploy GammaLoad first.
Gamaredon is officially linked to Russia's FSB and has a long record of targeting Ukrainian government, military, and critical infrastructure organizations with spear-phishing and booby-trapped archives. The report says the design is resilient, highly obfuscated, and adaptable enough to be reused in future operations.
The article also notes other Ukraine-focused clusters, including UAC-0184 and UAC-0247, and mentions PixyNetLoader in separate activity tied to APT28.
Key points
- Gamaredon is abusing WinRAR CVE-2025-8088 to launch a multi-stage malware chain.
- The chain begins with GammaPhish and GammaLoad, which fetch and run VBScript payloads.
- GammaWorm spreads via scheduled tasks, network shares, and USB drives while hiding with ADS and Telegram-based C2.
- GammaSteel steals files and sends them to an AWS S3 bucket or an attacker-controlled fallback server.
- Sekoia says the design is highly obfuscated, adaptable, and likely reusable in future operations.
Defenders have a clearer picture of the infection chain, which can help them look for GammaPhish, GammaLoad, GammaWorm, and GammaSteel instead of just a single malware sample. The report also gives security teams concrete clues such as Telegram use, scheduled tasks, ADS hiding, and S3 exfiltration paths.
The chain is modular and adaptable, so it can likely be repurposed for different malware families or objectives. If WinRAR exploitation, USB spread, and hidden persistence continue to work, the same campaign style could keep hitting Ukrainian targets with theft, espionage, or worse.



