INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FSB Group Gamaredon Hides Worm in Windows Data Streams
| 2026-06-01 11:00 CRITICAL HIGHExecutive Summary AI-generated
The Russian state-linked worm, known as GammaWorm, has been quietly spreading across Ukrainian networks while leaving almost no trace on infected machines. This latest tool of the long-running espionage group Gamaredon, formally tied to Russia's Federal Security Service (FSB), focuses almost entirely on Ukraine, targeting government, military, and critical infrastructure to steal sensitive documents and maintain long-term access. The worm exploits a path traversal flaw in WinRAR, a popular file compression software, which has been separately linked to other Russian operators like Sandworm, Turla, and others. GammaWorm's stealth becomes clear as it moves from hidden streams to fileless VBScript, showcasing the group's increasing sophistication.
Technical Mitigations AI-generated
• Update WinRAR to version 7.13 or later.
• Use a secure and up-to-date antivirus solution that can detect and block the worm's payload.
• Regularly back up critical data to prevent loss in case of infection.
• Keep operating systems, software, and firmware up to date with the latest security patches.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TurlaTurla
PteranodonPteranodon
CVE-2025-8088CVE-2025-8088
Target & Sectors
RU
UA
governmentgovernment
Incident Timeline
late December 2025
Sekoia's Threat Detection & Research team used a YARA rule in late December 2025 to target WinRAR vulnerabilities.
Click on any entity below to view its context and source!
organisation
Sekoia’s Threat Detection & Research
Sekoia’s Threat Detection & Research team dropped a YARA rule in late December 2025 to hunt for new initial access vectors, and by January 2026 it had already generated a dozen hits.
organisation
YARA
Sekoia’s Threat Detection & Research team dropped a YARA rule in late December 2025 to hunt for new initial access vectors, and by January 2026 it had already generated a dozen hits.
January 2026
Threat actors used a weaponized XHTML file as a spearphishing attachment to target compromised hosts.
Click on any entity below to view its context and source!
general_metric
70 samples
Working from artifacts on compromised hosts and more than 70 samples from a partner, the team reconstructed an infection chain seen in January 2026 and still active at the time of writing.
organisation
Sekoia’s Threat Detection & Research
Sekoia’s Threat Detection & Research team dropped a YARA rule in late December 2025 to hunt for new initial access vectors, and by January 2026 it had already generated a dozen hits.
organisation
YARA
Sekoia’s Threat Detection & Research team dropped a YARA rule in late December 2025 to hunt for new initial access vectors, and by January 2026 it had already generated a dozen hits.
2026/06/01
Gamaredon exploited a WinRAR vulnerability to launch its modular spy campaign on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
Click on any entity below to view its context and source!
infrastructure
Windows
A Russian state-linked worm has been observed hiding its components inside a little-used Windows file feature, allowing it to spread across Ukrainian networks while leaving almost no trace on infected machines.
FSB Group Gamaredon Hides Worm in Windows Data Streams.
Abusing the bug planted a hidden HTA file in the Windows Startup folder, which ran at the next login and fetched the next payload from a remote server.
Rather than dropping files on disk, the worm hid its modules in NTFS Alternate Data Streams, a native Windows feature that lets data ride alongside an existing file without appearing in standard directory listings.
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
This archive exploits the CVE-2025-8088 vulnerability to extract a hidden HTA file directly into the user’s Windows Startup directory.”
“
It actually contains two files: the visible decoy and an HTA file that path-traversal extracts directly into the user’s Windows Startup folder.
On the next login, Windows executes it automatically.
Instead it writes its core modules into NTFS Alternate Data Streams, a native Windows feature that lets data sit invisibly attached to a folder path, invisible to standard directory listings and not reflected in file sizes visible to users.
The malware maintains persistence through three scheduled tasks with names borrowed from legitimate Windows services:
DiskDiagnosticDataCollector
,
SilentCleanup
, and
SmartRetry
.
organisation
Sekoia
According to
new analysis
from Sekoia, the worm is the latest tool of
Gamaredon
, a long-running espionage group that Ukraine's security service has formally tied to Russia's Federal Security Service (FSB).
reads the
report
published by Sekoia.
organisation
Federal Security Service
According to
new analysis
from Sekoia, the worm is the latest tool of
Gamaredon
, a long-running espionage group that Ukraine's security service has formally tied to Russia's Federal Security Service (FSB).
infrastructure
Winrar
The archive exploited
CVE-2025-8088
, a path traversal flaw in WinRAR that Google's threat analysts have separately tied to
Sandworm
, Turla and other Russian operators.
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
A WinRAR Flaw Drops a Hidden File
The intrusion began with a booby-trapped xHTML file that, once opened, smuggled a malicious RAR archive onto the target's machine.
"
Organizations were also urged to update WinRAR to version 7.13 or later, which closes the flaw.
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets.
organisation
Google
The archive exploited
CVE-2025-8088
, a path traversal flaw in WinRAR that Google's threat analysts have separately tied to
Sandworm
, Turla and other Russian operators.
threat_actor
Turla
The archive exploited
CVE-2025-8088
, a path traversal flaw in WinRAR that Google's threat analysts have separately tied to
Sandworm
, Turla and other Russian operators.
Google’s Threat Intelligence Group documented the same CVE being exploited by Sandworm, Turla, and Gamaredon in the same timeframe, which suggests it moved fast across Russian operators after it was published.
organisation
APT
Russia-linked APT group Gamaredon (a.k.a.
Armageddon
,
Primitive Bear
,
ACTINIUM
,
Callisto
) has been active since 2014 and its activity focuses on Ukraine
The group was tied to the FSB by Ukraine’s Security Service, it originally used off-the-shelf tools like Remote Manipulator System RAT, then moved to a custom framework called
Pteranodon
, and gradually fragmented into a constellation of standalone, modular malware families.
organisation
FSB
Russia-linked APT group Gamaredon (a.k.a.
Armageddon
,
Primitive Bear
,
ACTINIUM
,
Callisto
) has been active since 2014 and its activity focuses on Ukraine
The group was tied to the FSB by Ukraine’s Security Service, it originally used off-the-shelf tools like Remote Manipulator System RAT, then moved to a custom framework called
Pteranodon
, and gradually fragmented into a constellation of standalone, modular malware families.
organisation
Ukraine’s Security Service
Russia-linked APT group Gamaredon (a.k.a.
Armageddon
,
Primitive Bear
,
ACTINIUM
,
Callisto
) has been active since 2014 and its activity focuses on Ukraine
The group was tied to the FSB by Ukraine’s Security Service, it originally used off-the-shelf tools like Remote Manipulator System RAT, then moved to a custom framework called
Pteranodon
, and gradually fragmented into a constellation of standalone, modular malware families.
organisation
Remote Manipulator System
Russia-linked APT group Gamaredon (a.k.a.
Armageddon
,
Primitive Bear
,
ACTINIUM
,
Callisto
) has been active since 2014 and its activity focuses on Ukraine
The group was tied to the FSB by Ukraine’s Security Service, it originally used off-the-shelf tools like Remote Manipulator System RAT, then moved to a custom framework called
Pteranodon
, and gradually fragmented into a constellation of standalone, modular malware families.
organisation
FSB Group Gamaredon Hides Worm
FSB Group Gamaredon Hides Worm in Windows Data Streams.
organisation
Windows Data Streams
FSB Group Gamaredon Hides Worm in Windows Data Streams.
organisation
HTA
Abusing the bug planted a hidden HTA file in the Windows Startup folder, which ran at the next login and fetched the next payload from a remote server.
This archive exploits the CVE-2025-8088 vulnerability to extract a hidden HTA file directly into the user’s Windows Startup directory.”
organisation
NTFS Alternate Data Streams
Rather than dropping files on disk, the worm hid its modules in NTFS Alternate Data Streams, a native Windows feature that lets data ride alongside an existing file without appearing in standard directory listings.
Instead it writes its core modules into NTFS Alternate Data Streams, a native Windows feature that lets data sit invisibly attached to a folder path, invisible to standard directory listings and not reflected in file sizes visible to users.
organisation
Telegram
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
For command-and-control (C2), GammaWorm pulled live server addresses from legitimate public services, including Telegram and Cloudflare and used them as dead drops before saving the details to the registry.
organisation
WinRAR
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
organisation
USB
It then propagated to USB sticks and network drives, hiding genuine folders and swapping them for malicious shortcuts that carried provocative Ukrainian-language filenames meant to lure users into opening them.
The propagation module targets USB drives and network shares.
organisation
RAR
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
A WinRAR Flaw Drops a Hidden File
The intrusion began with a booby-trapped xHTML file that, once opened, smuggled a malicious RAR archive onto the target's machine.
infrastructure
7.13
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
"
Organizations were also urged to update WinRAR to version 7.13 or later, which closes the flaw.
organisation
XHTML
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
organisation
HTML
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
organisation
CVE-2025
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
organisation
Gamaredon Uses WinRAR Vulnerability
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets.
organisation
Launch Modular Spy Campaign
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets.
organisation
VBScript
The campaign has moved almost entirely to fileless VBScript, a clear step up in stealth from Gamaredon's earlier tooling.
“
GammaLoad (Staging):
We recovered multiple VBScript loaders from the compromised hosts.
organisation
Gamaredon
The campaign has moved almost entirely to fileless VBScript, a clear step up in stealth from Gamaredon's earlier tooling.
Sekoia researchers found a
Gamaredon
infection chain that’s more modular, more evasive, and more persistent than anything the group had publicly deployed before.
organisation
PDF
A decoy PDF kept the victim unaware.
The archive looks like it contains one PDF.
organisation
GammaWorm
For command-and-control (C2), GammaWorm pulled live server addresses from legitimate public services, including Telegram and Cloudflare and used them as dead drops before saving the details to the registry.
Sekoia has now aligned the naming under a single taxonomy using the “Gamma” prefix: GammaPhish for initial access, GammaLoad for staging, GammaWorm for propagation, GammaSteel for data theft, and GammaWipe for destruction.
organisation
Cloudflare
For command-and-control (C2), GammaWorm pulled live server addresses from legitimate public services, including Telegram and Cloudflare and used them as dead drops before saving the details to the registry.
What’s new is the infrastructure concealment: running almost entirely in memory, storing payloads in ADS, resolving C2s through Telegram and Cloudflare, and exfiltrating data in HTTP headers rather than request bodies.
organisation
GammaSteel
Sekoia has now aligned the naming under a single taxonomy using the “Gamma” prefix: GammaPhish for initial access, GammaLoad for staging, GammaWorm for propagation, GammaSteel for data theft, and GammaWipe for destruction.
organisation
DDR
Sekoia warned that the safest response to infection is a full wipe: "The malware's reliance on Dead Drop Resolvers (DDR) allows it to constantly download fresh payloads, meaning that cleaning attempts often result in fallback mechanisms restoring the malware.
organisation
SecurityAffairs
The definitive transition to a nearly
entirely fileless, VBScript-driven “matryoshka” architecture,
combined with the heavy abuse of
NTFS Alternate Data Streams (ADS)
, demonstrates a concerted effort to bypass automated sandboxes, complicate forensic artifact recovery, and ultimately exhaust defenders.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Russia)
organisation
Cloudflare Workers
The C2 resolution chain itself is layered: it hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph, and Telegram before arriving at an operator-controlled server.
organisation
Teletype
The C2 resolution chain itself is layered: it hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph, and Telegram before arriving at an operator-controlled server.
organisation
Telegra.ph
The C2 resolution chain itself is layered: it hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph, and Telegram before arriving at an operator-controlled server.
organisation
GammaLoad
This is part one of a three-part series; parts two and three cover
GammaLoad
and
GammaSteel,
respectively.
organisation
Supabase
Opening it silently triggers a 1×1 pixel tracking request to a Supabase endpoint, confirming to the operator that the victim opened the lure.
organisation
ADS
Each one executes a different ADS module at short intervals, from 7 to 10 minutes.
organisation
RunOnce
GammaWorm also writes a
RunOnce
registry key that recreates itself on every user login, because GammaWorm itself rewrites the key before the
RunOnce
entry gets deleted.
organisation
Hidden and System
It hides real folders by setting their attributes to Hidden and System, then drops malicious LNK shortcut files in their place using the same folder name and icon.
organisation
LNK
It hides real folders by setting their attributes to Hidden and System, then drops malicious LNK shortcut files in their place using the same folder name and icon.
organisation
Explorer
Clicking the LNK opens the real folder in Explorer so the user sees nothing wrong, while silently executing
~.gif
, the worm file that sits at the root of every infected drive.
organisation
IP
To find its C2 address, GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address, and posts the victim’s machine fingerprint back via randomized HTTP headers, specifically inside the User-Agent string.
organisation
C2 IP
Sekoia notes that for any host confirmed infected by this chain, a complete wipe is the safest remediation path, because GammaWorm’s dead-drop resolution lets operators push fresh payloads faster than cleaning attempts can keep up.
IOCs including file hashes for GammaPhish and GammaWorm, dead drop resolver URLs, and the single confirmed C2 IP are published at the end of the Sekoia report.
organisation
Gamaredon’s
“However, this campaign marks a significant technical step up over Gamaredon’s previously documented attacks.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
A Russian state-linked worm has been observed hiding its components inside a little-used Windows file feature, allowing it to spread across Ukrainian networks while leaving almost no trace on infected machines.
FSB Group Gamaredon Hides Worm in Windows Data Streams.
Abusing the bug planted a hidden HTA file in the Windows Startup folder, which ran at the next login and fetched the next payload from a remote server.
Rather than dropping files on disk, the worm hid its modules in NTFS Alternate Data Streams, a native Windows feature that lets data ride alongside an existing file without appearing in standard directory listings.
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
This archive exploits the CVE-2025-8088 vulnerability to extract a hidden HTA file directly into the user’s Windows Startup directory.”
“
It actually contains two files: the visible decoy and an HTA file that path-traversal extracts directly into the user’s Windows Startup folder.
On the next login, Windows executes it automatically.
Instead it writes its core modules into NTFS Alternate Data Streams, a native Windows feature that lets data sit invisibly attached to a folder path, invisible to standard directory listings and not reflected in file sizes visible to users.
The malware maintains persistence through three scheduled tasks with names borrowed from legitimate Windows services:
DiskDiagnosticDataCollector
,
SilentCleanup
, and
SmartRetry
.
Metrics
infrastructure
Winrar
Affected Product
The archive exploited
CVE-2025-8088
, a path traversal flaw in WinRAR that Google's threat analysts have separately tied to
Sandworm
, Turla and other Russian operators.
A WinRAR Flaw Drops a Hidden File
The intrusion began with a booby-trapped xHTML file that, once opened, smuggled a malicious RAR archive onto the target's machine.
"
Organizations were also urged to update WinRAR to version 7.13 or later, which closes the flaw.
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets.
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
Metrics
infrastructure
7.13
Software Version
"
Organizations were also urged to update WinRAR to version 7.13 or later, which closes the flaw.
The XHTML then uses HTML smuggling to deliver a RAR archive that exploits
CVE-2025-8088
, a critical path traversal flaw in WinRAR patched in version 7.13.
Intelligence Sources
Infosecurity-Magazine
2026-06-01
FSB Group Gamaredon Hides Worm in Windows Data Streams
Infosecurity-Magazine
Security Affairs
2026-06-04
Infosecurity-Magazine
2026-06-01
FSB Group Gamaredon Hides Worm in Windows Data Streams
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-25T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
43x
organisation
Identified Entity
Sekoia
entity
4x
timeline
Temporal Reference
7.13 or later
date
3x
attribution
Attributing Entity
Google
authority
2x
source region
Origin Country
Russian Federation
country
2x
infrastructure
Affected Product
Windows
software
2x
target region
Target Country
Ukraine
country
2x
tactic
Cyber Operation Type
Espionage
tactic
Contextual Telemetry
Context Block
11 METRICS
industry
Targeted Sector
Government
sector
vulnerability
Exploited CVE
CVE-2025-8088
cve
threat actor
APT Group
Turla
actor
infrastructure
Software Version
7.13
version
general metric
Samples
70
samples
malware
Malware Payload
Pteranodon
tool
general metric
Version
7
version
general metric
Minutes
10
minutes
general metric
Lines
20,000
lines
general metric
Returns
200
returns
general metric
Entities
404
entities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.