Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers
Gamaredon
IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA (GammaPhish) into Startup. The HTA runs mshta against an operator URL (padded with a www.bbc.com decoy path) to fetch GammaLoad, an in-memory VBScript loader cascade that resolves and registry-caches its C2 through dead-drop resolvers on graph.org/Telegra.ph, Teletype.in, public Telegram channels, Write.as, Rentry.co, Mastodon and Cloudflare Workers, with Cloudflare quick tunnels fronting the operator origin. The operator runs a rapidly rotated fleet of dedicated hosts (55 servers in 12 days, ~24h average lifespan) that serve VBScript and signal via HTTP 200/404. GammaLoad deploys GammaWorm (propagation) and GammaSteel (fileless PowerShell stealer), which exfiltrates documents to the S3-compatible Tebi.io/AWS S3 with fallback to hard-coded operator domains.
latest published chain