INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FSB Group Gamaredon Hides Worm in Windows Data Streams

| 2026-06-01 11:00 CRITICAL HIGH
Executive Summary AI-generated
The Russian state-linked worm, known as GammaWorm, has been quietly spreading across Ukrainian networks while leaving almost no trace on infected machines. This latest tool of the long-running espionage group Gamaredon, formally tied to Russia's Federal Security Service (FSB), focuses almost entirely on Ukraine, targeting government, military, and critical infrastructure to steal sensitive documents and maintain long-term access. The worm exploits a path traversal flaw in WinRAR, a popular file compression software, which has been separately linked to other Russian operators like Sandworm, Turla, and others. GammaWorm's stealth becomes clear as it moves from hidden streams to fileless VBScript, showcasing the group's increasing sophistication.
Technical Mitigations AI-generated
• Update WinRAR to version 7.13 or later. • Use a secure and up-to-date antivirus solution that can detect and block the worm's payload. • Regularly back up critical data to prevent loss in case of infection. • Keep operating systems, software, and firmware up to date with the latest security patches.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TurlaTurla PteranodonPteranodon CVE-2025-8088CVE-2025-8088
Target & Sectors
RU UA
governmentgovernment
Incident Timeline
‎late December 2025
Sekoia's Threat Detection & Research team used a YARA rule in late December 2025 to target WinRAR vulnerabilities.
organisation Sekoia’s Threat Detection & Research
organisation YARA
‎January 2026
Threat actors used a weaponized XHTML file as a spearphishing attachment to target compromised hosts.
general_metric 70 samples
organisation Sekoia’s Threat Detection & Research
organisation YARA
‎2026/06/01
Gamaredon exploited a WinRAR vulnerability to launch its modular spy campaign on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram.
infrastructure Windows
organisation Sekoia
organisation Federal Security Service
infrastructure Winrar
organisation Google
threat_actor Turla
organisation APT
organisation FSB
organisation Ukraine’s Security Service
organisation Remote Manipulator System
organisation FSB Group Gamaredon Hides Worm
organisation Windows Data Streams
organisation HTA
organisation NTFS Alternate Data Streams
organisation Telegram
organisation WinRAR
organisation USB
organisation RAR
infrastructure 7.13
organisation XHTML
organisation HTML
organisation CVE-2025
organisation Gamaredon Uses WinRAR Vulnerability
organisation Launch Modular Spy Campaign
organisation VBScript
organisation Gamaredon
organisation PDF
organisation GammaWorm
organisation Cloudflare
organisation GammaSteel
organisation DDR
organisation SecurityAffairs
organisation Cloudflare Workers
organisation Teletype
organisation Telegra.ph
organisation GammaLoad
organisation Supabase
organisation ADS
organisation RunOnce
organisation Hidden and System
organisation LNK
organisation Explorer
organisation IP
organisation C2 IP
organisation Gamaredon’s
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Winrar
Affected Product
Metrics
infrastructure
‎7.13
Software Version
Intelligence Sources
Infosecurity-Magazine 2026-06-01
Infosecurity-Magazine 2026-06-01